Show filters
129 Total Results
Displaying 11-20 of 129
Sort by:
Attacker Value
Unknown
CVE-2021-21558
Disclosure Date: May 13, 2021 (last updated February 22, 2025)
Dell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator of the gstd system may potentially exploit this vulnerability to read LDAP credentials from local logs and use the stolen credentials to make changes to the network domain.
0
Attacker Value
Unknown
CVE-2021-32074
Disclosure Date: May 07, 2021 (last updated February 22, 2025)
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.
0
Attacker Value
Unknown
CVE-2021-20536
Disclosure Date: April 24, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
0
Attacker Value
Unknown
CVE-2021-31546
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppression deletions, which should not have been visible to users with access to view AbuseFilter log data.
0
Attacker Value
Unknown
CVE-2021-3037
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to export the PAN-OS configuration to the destination server.
0
Attacker Value
Unknown
CVE-2021-3036
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that are configured to use the PAN-OS XML API and exists only when a client includes a duplicate API parameter in API requests. Logged information includes the cleartext username, password, and API key of the administrator making the PAN-OS XML API request.
0
Attacker Value
Unknown
CVE-2021-26908
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.
0
Attacker Value
Unknown
CVE-2021-24024
Disclosure Date: April 12, 2021 (last updated February 22, 2025)
A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and below may allow a remote authenticated attacker to read other local users' password in log files.
0
Attacker Value
Unknown
CVE-2021-23924
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
0
Attacker Value
Unknown
CVE-2021-3447
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the no_log feature. An attacker can take advantage of this information to steal those credentials, provided when they have access to the log files containing them. The highest threat from this vulnerability is to data confidentiality. This flaw affects Red Hat Ansible Automation Platform in versions before 1.2.2 and Ansible Tower in versions before 3.8.2.
0