VYPR

CWE-1295

Debug Messages Revealing Unnecessary Information

BaseIncomplete

Description

The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-121

CVEs mapped to this weakness (23)

page 2 of 2
  • CVE-2022-27597LowMar 29, 2023
    risk 0.18cvss 2.7epss 0.01

    A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP…

  • CVE-2023-25500LowJun 22, 2023
    risk 0.16cvss 3.5epss 0.01

    Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified…

  • CVE-2021-31412MedJun 24, 2021
    risk 0.00cvss 5.3epss 0.01

    Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), and 3.0.0 through 6.0.9…