CWE-1230
Exposure of Sensitive Information Through Metadata
Description
The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.
Hierarchy (View 1000)
CVEs mapped to this weakness (26)
page 1 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-9099 | Hig | 0.53 | 8.1 | 0.01 | Mar 20, 2025 | In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This vulnerability allows unauthorized users to retrieve sensitive credentials,… | ||
| CVE-2025-13084 | Hig | 0.49 | 7.6 | 0.00 | Nov 26, 2025 | The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators. | ||
| CVE-2025-47324 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Information disclosure while accessing and modifying the PIB file of a remote device via powerline. | ||
| CVE-2025-0330 | Hig | 0.49 | 7.5 | 0.01 | Mar 20, 2025 | In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full… | ||
| CVE-2024-53291 | Hig | 0.49 | 7.5 | 0.00 | Dec 25, 2024 | Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | ||
| CVE-2025-30038 | Hig | 0.47 | — | 0.00 | Aug 27, 2025 | The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially… | ||
| CVE-2024-47517 | Med | 0.44 | 6.8 | 0.00 | Jan 10, 2025 | Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access | ||
| CVE-2025-59601 | Med | 0.42 | 6.5 | 0.00 | Jun 1, 2026 | Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration. | ||
| CVE-2024-9447 | Med | 0.42 | 6.5 | 0.01 | Mar 20, 2025 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any… | ||
| CVE-2025-1921 | Med | 0.42 | 6.5 | 0.00 | Mar 5, 2025 | Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-49270 | Med | 0.38 | 5.9 | 0.00 | Jun 1, 2026 | Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive… | ||
| CVE-2023-1974 | Med | 0.35 | 6.5 | 0.01 | Apr 11, 2023 | Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8. | ||
| CVE-2024-49395 | Med | 0.34 | 5.3 | 0.00 | Nov 12, 2024 | In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info. | ||
| CVE-2023-6962 | Med | 0.34 | 5.3 | 0.00 | May 2, 2024 | The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description… | ||
| CVE-2023-32488 | Med | 0.34 | 5.3 | 0.00 | Aug 16, 2023 | Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure. | ||
| CVE-2026-27661 | Med | 0.28 | 4.3 | 0.00 | Mar 10, 2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`. | ||
| CVE-2026-29055 | Med | 0.27 | 5.3 | 0.00 | Mar 26, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the image processing pipeline in Tandoor Recipes explicitly skips EXIF metadata stripping, image rescaling, and size validation for WebP and GIF image… | ||
| CVE-2025-31959 | Low | 0.23 | 3.5 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. . | ||
| CVE-2023-50458 | Low | 0.23 | 3.5 | 0.00 | Jul 10, 2025 | In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs. | ||
| CVE-2026-45544 | Med | 0.21 | 4.3 | 0.00 | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0. |
- risk 0.53cvss 8.1epss 0.01
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This vulnerability allows unauthorized users to retrieve sensitive credentials,…
- risk 0.49cvss 7.6epss 0.00
The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
- risk 0.49cvss 7.5epss 0.00
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
- risk 0.49cvss 7.5epss 0.01
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full…
- risk 0.49cvss 7.5epss 0.00
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
- risk 0.47cvss —epss 0.00
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially…
- risk 0.44cvss 6.8epss 0.00
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
- risk 0.42cvss 6.5epss 0.01
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any…
- risk 0.42cvss 6.5epss 0.00
Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.38cvss 5.9epss 0.00
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive…
- risk 0.35cvss 6.5epss 0.01
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.
- risk 0.34cvss 5.3epss 0.00
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
- risk 0.34cvss 5.3epss 0.00
The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description…
- risk 0.34cvss 5.3epss 0.00
Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
- risk 0.28cvss 4.3epss 0.00
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`.
- risk 0.27cvss 5.3epss 0.00
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the image processing pipeline in Tandoor Recipes explicitly skips EXIF metadata stripping, image rescaling, and size validation for WebP and GIF image…
- risk 0.23cvss 3.5epss 0.00
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
- risk 0.23cvss 3.5epss 0.00
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
- risk 0.21cvss 4.3epss 0.00
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.