CVEbaza.plSłownik CWECWE-1295
Common Weakness Enumeration

CWE-1295

Debug Messages Revealing Unnecessary Information

Kategoria: BaseCVE: 22
Opis

Produkt nie zapobiega wystarczająco ujawnianiu niepotrzebnych i potencjalnie wrażliwych informacji systemowych w wiadomościach debugowania. Może to prowadzić do ekspozycji danych bezpieczeństwa przed nieuprawnionym dostępem.

Description (EN)

The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.

Podatności CVE z CWE-1295 (22)
9.3
CVSS
CRITICAL
CVE-2026-48797

Biblioteka Python Backpropagate (wersje 1.1.0 i 1.1.1) eksponuje interfejs webowy Reflex do sterowania procesem trenowania modeli językowych bez jakiegokolwiek uwierzytelnienia, mimo że dokumentacja oraz flaga --auth sugerowały odwrotnie. Podatność jest szczególnie groźna, ponieważ operator może nieświadomie udostępnić niezabezpieczony panel publicznie poprzez flagę --share.

pub. 2026-06-17
8.8
CVSS
HIGH
CVE-2024-38516

ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in versions 2024.04.7, 2023.10.15, 2022.10.13 and 2021.10.22.

pub. 2024-06-25
7.5
CVSS
HIGH
CVE-2026-28811

Apache JSPWiki w wersjach do 2.12.3 włącznie ujawnia zbędne informacje poprzez komunikaty debugowania. Podatność umożliwia nieuwierzytelnionemu atakującemu zdalne pozyskanie wrażliwych danych systemowych.

pub. 2026-07-30
7.5
CVSS
HIGH
CVE-2025-31001

Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit gtm-kit allows Retrieve Embedded Sensitive Data.This issue affects GTM Kit: from n/a through <= 2.4.0.

pub. 2025-04-01
7.5
CVSS
HIGH
CVE-2024-45784

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users could access these logs, potentially exposing critical data that could be exploited to compromise the security of the Airflow deployment. In version 2.10.3, secrets are now masked in task logs to prevent sensitive configuration variables from being exposed in the logging output. Users should upgrade to Airflow 2.10.3 or the latest version to eliminate this vulnerability. If you suspect that DAG authors could have logged the secret values to the logs and that your logs are not additionally protected, it is also recommended that you update those secrets.

pub. 2024-11-15
7.5
CVSS
HIGH
CVE-2023-5392

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

pub. 2024-04-11
6.9
CVSS
MEDIUM
CVE-2025-42604

This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unauthorized API endpoints leading to detailed error messages as response leading to disclosure of system related information.

pub. 2025-04-23
6.5
CVSS
MEDIUM
CVE-2025-2877

A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.

pub. 2025-03-28
6.5
CVSS
MEDIUM
CVE-2023-4215

Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.

pub. 2023-10-17
6.2
CVSS
MEDIUM
CVE-2025-12910

Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: Low)

pub. 2025-11-08
5.5
CVSS
MEDIUM
CVE-2025-46775

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.

pub. 2025-11-18
5.3
CVSS
MEDIUM
CVE-2021-31412

Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), and 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows network attacker to enumerate all available routes via crafted HTTP request when application is running in production mode and no custom handler for NotFoundException is provided.

pub. 2021-06-24
5.1
CVSS
MEDIUM
CVE-2025-59109

Urządzenia rejestracyjne dormakaba 9002 (PIN Pad Units) posiadają odsłonięty nagłówek UART na panelu tylnym. Pad PIN wysyła każde naciśnięcie przycisku do interfejsu UART. Atakujący może wykorzystać ten interfejs do eksfiltracji numerów PIN. Ponieważ urządzenia są jawnie zbudowane jako Plug-and-Play dla łatwej wymiany, atakujący może łatwo usunąć urządzenie, zainstalować sprzętowy implant podłączony do UART i eksfiltrować dane do innego systemu (np. poprzez WiFi).

pub. 2026-01-26
4.9
CVSS
MEDIUM
CVE-2024-11217

A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.

pub. 2024-11-15
4.7
CVSS
MEDIUM
CVE-2024-27179

Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the reference URL.

pub. 2024-06-14
4.6
CVSS
MEDIUM
CVE-2025-35031

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.

pub. 2025-09-29
4.4
CVSS
MEDIUM
CVE-2023-28077

Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to a locally privileged user.

pub. 2024-02-10
4.4
CVSS
MEDIUM
CVE-2022-34364

Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to a locally privileged user. .

pub. 2023-02-10
4.1
CVSS
MEDIUM
CVE-2021-25476

An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.

pub. 2021-10-06
3.9
CVSS
LOW
CVE-2025-20643

W DA istnieje możliwość out of bounds read z powodu braku sprawdzenia granic. Może to prowadzić do local information disclosure, jeśli atakujący ma fizyczny dostęp do urządzenia i już uzyskał uprawnienia System. Exploitacja wymaga interakcji użytkownika. Patch ID: ALPS09291146; Issue ID: MSV-2056.

pub. 2025-02-03
Pokazano 20 z 22 podatności
Informacje
ID: CWE-1295
Typ: Base
Podatności: 22
MITRE CWE ↗
← Słownik CWE