VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 6 of 30
  • CVE-2023-46240HigOct 31, 2023
    risk 0.42cvss 7.5epss 0.01

    CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be leaked. Version 4.4.3 contains a patch.…

  • CVE-2023-28117HigMar 22, 2023
    risk 0.42cvss 7.6epss 0.01

    Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific configuration it is possible to leak sensitive cookies values, including the session cookie to…

  • CVE-2023-25956HigFeb 24, 2023
    risk 0.42cvss 7.5epss 0.01

    Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.1.

  • CVE-2022-22760MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97,…

  • CVE-2022-31140HigJul 11, 2022
    risk 0.42cvss 7.5epss 0.01

    Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12.0, Valinor can use `Throwable#getMessage()` when it should not have permission to do so. This is a problem with cases such as an SQL exception showing an SQL…

  • CVE-2022-2062HigJun 13, 2022
    risk 0.42cvss 7.5epss 0.01

    Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2021-39033MedApr 19, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks…

  • CVE-2022-0660HigFeb 18, 2022
    risk 0.42cvss 7.5epss 0.07

    Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2021-43542MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.02

    Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-39458MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

  • CVE-2021-26997MedJun 11, 2021
    risk 0.42cvss 6.5epss 0.01

    E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging which may aid in crafting more complex attacks.

  • CVE-2021-20371MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.

  • CVE-2021-23973MedFeb 26, 2021
    risk 0.42cvss 6.5epss 0.01

    When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

  • CVE-2020-15666MedOct 1, 2020
    risk 0.42cvss 6.5epss 0.01

    When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to…

  • CVE-2020-6511MedJul 22, 2020
    risk 0.42cvss 6.5epss 0.02

    Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6503MedJun 3, 2020
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2020-4085MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    "HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."

  • CVE-2019-13697MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-3756MedSep 18, 2019
    risk 0.42cvss 6.5epss 0.01

    RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions.

  • CVE-2018-10913MedSep 4, 2018
    risk 0.42cvss 6.5epss 0.02

    An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.