VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 8 of 30
  • CVE-2021-23135MedMay 12, 2021
    risk 0.38cvss 5.9epss 0.00

    Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7.14.

  • CVE-2020-14337MedJul 31, 2020
    risk 0.38cvss 5.8epss 0.01

    A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this…

  • CVE-2025-23216MedJan 30, 2025
    risk 0.37cvss 6.8epss 0.00

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes…

  • CVE-2026-20838MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2025-40760MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly handle error messages and discloses sensitive password hash information when processing user authentication requests. This could allow a local attacker to…

  • CVE-2025-55676MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.

  • CVE-2025-53803MedSep 9, 2025
    risk 0.36cvss 5.5epss 0.01

    Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2025-22421MedSep 2, 2025
    risk 0.36cvss 5.5epss 0.00

    In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2025-5731MedJun 26, 2025
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

  • CVE-2024-6613MedJul 9, 2024
    risk 0.36cvss 5.5epss 0.00

    The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.

  • CVE-2021-47381MedMay 21, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Fix DSP oops stack dump output contents Fix @buf arg given to hex_dump_to_buffer() and stack address used in dump error output.

  • CVE-2021-47161MedMar 25, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-dspi: Fix a resource leak in an error handling path 'dspi_request_dma()' should be undone by a 'dspi_release_dma()' call in the error handling path of the probe function, as already done in the…

  • CVE-2023-4457MedOct 16, 2023
    risk 0.36cvss 5.5epss 0.00

    Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially…

  • CVE-2023-31429MedAug 1, 2023
    risk 0.36cvss 5.5epss 0.00

    Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgdisable and supportshowcfgenable commands…

  • CVE-2023-20593MedJul 24, 2023
    risk 0.36cvss 5.5epss 0.05

    An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

  • CVE-2023-21103MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-0563MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message…

  • CVE-2021-1546MedSep 23, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnerability by running a CLI…

  • CVE-2021-30357MedJun 8, 2021
    risk 0.36cvss 5.3epss 0.23

    SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

  • CVE-2019-12864MedMay 4, 2020
    risk 0.36cvss 5.5epss 0.00

    SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the…