VYPR

CWE-1258

Exposure of Sensitive System Information Due to Uncleared Debug Information

BaseDraft

Description

The hardware does not fully clear security-sensitive values, such as keys and intermediate values in cryptographic operations, when debug mode is entered.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-204 · CAPEC-37 · CAPEC-545

CVEs mapped to this weakness (5)

  • CVE-2025-15480CriApr 9, 2026
    risk 0.52cvss 9.1epss 0.00

    In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.

  • CVE-2025-14551HigApr 9, 2026
    risk 0.46cvss 8.1epss 0.00

    In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the…

  • CVE-2025-32257MedApr 4, 2025
    risk 0.35cvss 5.3epss 0.01

    Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7.

  • CVE-2022-39292Oct 10, 2022
    risk 0.00cvss epss 0.01

    Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 which redacts sensitive URLs for webhooks. As a workaround,…

  • CVE-2022-31162Jul 21, 2022
    risk 0.00cvss epss 0.01

    Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug logs. Stricter and more secure debug formatting was introduced in v0.41.0 for OAuth secret types to reduce the possibility of…