VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (628)

page 32 of 32
  • CVE-2021-25958MedAug 30, 2021
    risk 0.00cvss 6.5epss 0.03

    In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with…

  • CVE-2021-32734LowJul 12, 2021
    risk 0.00cvss 3.1epss 0.01

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to the user. This could result in a full path disclosure on…

  • CVE-2020-23995MedMay 13, 2021
    risk 0.00cvss 6.5epss 0.02

    An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.

  • CVE-2020-35177MedDec 17, 2020
    risk 0.00cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.

  • CVE-2020-25633MedSep 18, 2020
    risk 0.00cvss 5.3epss 0.01

    A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this…

  • CVE-2020-15125HigJul 29, 2020
    risk 0.00cvss 7.7epss 0.02

    In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged…

  • CVE-2019-11252MedJul 23, 2020
    risk 0.00cvss 5.9epss 0.01

    The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.

  • CVE-2000-1191Aug 31, 2001
    risk 0.00cvss —epss 0.03

    htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.