CWE-1230
Exposure of Sensitive Information Through Metadata
Description
The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.
Hierarchy (View 1000)
CVEs mapped to this weakness (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-13084 | Hig | 0.49 | 7.6 | 0.00 | Nov 26, 2025 | The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators. | ||
| CVE-2025-30038 | Hig | 0.47 | — | 0.00 | Aug 27, 2025 | The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially… | ||
| CVE-2025-59601 | Med | 0.42 | 6.5 | 0.00 | Jun 1, 2026 | Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration. | ||
| CVE-2026-49270 | Med | 0.38 | 5.9 | 0.00 | Jun 1, 2026 | Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive… | ||
| CVE-2023-6962 | Med | 0.34 | 5.3 | 0.00 | May 2, 2024 | The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description… | ||
| CVE-2025-31959 | Low | 0.23 | 3.5 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. . | ||
| CVE-2026-45544 | Med | 0.21 | 4.3 | 0.00 | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0. | ||
| CVE-2025-8713 | Low | 0.20 | 3.1 | 0.00 | Aug 14, 2025 | PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data… | ||
| CVE-2025-0330 | — | 0.00 | — | 0.01 | Mar 20, 2025 | In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full… | ||
| CVE-2025-26527 | 0.00 | — | 0.00 | Feb 24, 2025 | Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block. | |||
| CVE-2023-1974 | — | 0.00 | — | 0.01 | Apr 11, 2023 | Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8. |
- risk 0.49cvss 7.6epss 0.00
The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
- risk 0.47cvss —epss 0.00
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially…
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
- risk 0.38cvss 5.9epss 0.00
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive…
- risk 0.34cvss 5.3epss 0.00
The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description…
- risk 0.23cvss 3.5epss 0.00
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
- risk 0.21cvss 4.3epss 0.00
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.
- risk 0.20cvss 3.1epss 0.00
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data…
- CVE-2025-0330Mar 20, 2025risk 0.00cvss —epss 0.01
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full…
- CVE-2025-26527Feb 24, 2025risk 0.00cvss —epss 0.00
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
- CVE-2023-1974Apr 11, 2023risk 0.00cvss —epss 0.01
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.