Common Weakness Enumeration

CWE-209

Allowed

Generation of Error Message Containing Sensitive Information

Abstraction: Base · Status: Draft

The product generates an error message that includes sensitive information about its environment, users, or associated data.

956 vulnerabilities reference this CWE, most recent first.

GHSA-2VVG-J984-HH8P

Vulnerability from github – Published: 2025-07-10 18:31 – Updated: 2026-03-16 18:32
VLAI
Details

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-47813"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-07-10T17:15:47Z",
    "severity": "MODERATE"
  },
  "details": "loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.",
  "id": "GHSA-2vvg-j984-hh8p",
  "modified": "2026-03-16T18:32:02Z",
  "published": "2025-07-10T18:31:27Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47813"
    },
    {
      "type": "WEB",
      "url": "https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-47813.txt"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-47813"
    },
    {
      "type": "WEB",
      "url": "https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812"
    },
    {
      "type": "WEB",
      "url": "https://www.wftpserver.com"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-2W6R-VQMF-FP8M

Vulnerability from github – Published: 2026-07-30 21:31 – Updated: 2026-07-30 21:31
VLAI
Details

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-11904"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-07-30T19:17:04Z",
    "severity": "MODERATE"
  },
  "details": "IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.",
  "id": "GHSA-2w6r-vqmf-fp8m",
  "modified": "2026-07-30T21:31:48Z",
  "published": "2026-07-30T21:31:48Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11904"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7279510"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-2WX3-WGWM-8JH9

Vulnerability from github – Published: 2023-12-15 12:30 – Updated: 2023-12-15 12:30
VLAI
Details

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-6839"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-12-15T11:15:48Z",
    "severity": "MODERATE"
  },
  "details": "Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.\n\n",
  "id": "GHSA-2wx3-wgwm-8jh9",
  "modified": "2023-12-15T12:30:32Z",
  "published": "2023-12-15T12:30:32Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6839"
    },
    {
      "type": "WEB",
      "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1334"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-2XWV-3CC9-FP7C

Vulnerability from github – Published: 2019-09-11 23:07 – Updated: 2020-08-31 18:49
VLAI
Summary
Sensitive Data Exposure in seneca
Details

Versions of seneca prior to 3.9.0 are vulnerable to Sensitive Data Exposure. When a process using the package crashes all environment variables are printed. This may leak sensitive data such as access keys, especially given scenarios when log-monitoring systems store the error output.

Recommendation

Upgrade to version 3.9.0 or later.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "seneca"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.9.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2019-5483"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2019-09-11T22:45:13Z",
    "nvd_published_at": null,
    "severity": "LOW"
  },
  "details": "Versions of `seneca` prior to 3.9.0 are vulnerable to Sensitive Data Exposure. When a process using the package crashes all environment variables are printed. This may leak sensitive data such as access keys, especially given scenarios when log-monitoring systems store the error output.\n\n\n## Recommendation\n\nUpgrade to version 3.9.0 or later.",
  "id": "GHSA-2xwv-3cc9-fp7c",
  "modified": "2020-08-31T18:49:15Z",
  "published": "2019-09-11T23:07:57Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-5483"
    },
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/526258"
    },
    {
      "type": "WEB",
      "url": "https://github.com/nodejs/security-wg/blob/master/vuln/npm/501.json"
    },
    {
      "type": "WEB",
      "url": "https://www.npmjs.com/advisories/1155"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [],
  "summary": "Sensitive Data Exposure in seneca"
}

GHSA-32H9-HQHX-9J29

Vulnerability from github – Published: 2024-11-04 15:31 – Updated: 2024-11-08 15:31
VLAI
Details

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API request leading to generation of error message containing sensitive information on the targeted system.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-51560"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-11-04T13:17:05Z",
    "severity": "HIGH"
  },
  "details": "This vulnerability exists in the Wave 2.0\u00a0due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for \u201cuserId\u201d parameter in the API request leading to generation of error message containing sensitive information on the targeted system.",
  "id": "GHSA-32h9-hqhx-9j29",
  "modified": "2024-11-08T15:31:12Z",
  "published": "2024-11-04T15:31:57Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51560"
    },
    {
      "type": "WEB",
      "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01\u0026VLCODE=CIVN-2024-0332"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-3325-V43H-43RV

Vulnerability from github – Published: 2026-10-01 15:21 – Updated: 2026-10-01 15:21
VLAI
Summary
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Details

JupyterLab's PyPI extension manager runs python -m pip uninstall with the extension name taken from the request body. ExtensionHandler.post validates the name for cmd=install but not for cmd=uninstall, so a name that begins with - reaches the command line and pip reads it as an option rather than as a package.

cmdline = [
    sys.executable,
    "-m",
    "pip",
    "uninstall",
    "--yes",
    "--no-input",
    extension,
]

An extension name of the form -r followed by a path therefore made pip open that path as a requirements file. pip's parse error quotes the line it could not read and names the file it came from, and JupyterLab returned that error in the response body, so the line reached the requester.

This has security implications only for deployments that combine all of the following:

  • the (default) PyPI Extension Manager enabled, so that uninstall requests reach pip;
  • an authenticated account permitted to call the extension API; and
  • kernels and terminals disabled or delegated to remote hosts (otherwise a user with kernel access can read the same files and make the same outbound requests directly, regardless of this endpoint)

Unlike GHSA-37w4-hwhx-4rc4 and GHSA-89vp-jrxv-24w8, this does not need an allowlist or blocklist to be configured. The uninstall path never consulted the listing.

Impact

An authenticated user gains a read of server-side files and an outbound request from the server, both outside the confinement that the contents root and the disabled kernels were meant to provide. The user cannot choose which line of a file is returned, and cannot write content of their choosing.

Reading files the account cannot reach

-r<path> makes pip open the path as a requirements file. The first line that pip cannot parse as a requirement comes back in the response together with the path. Blank lines and # comments are skipped. A line that is a valid package name is accepted silently, and the request answers 201 with no message, so a secret made only of letters, digits, dots, hyphens and underscores is not disclosed. One line is returned per request, and the requester cannot select which one.

The same option distinguishes a missing path ([Errno 2] No such file or directory), an unreadable one ([Errno 13] Permission denied) and a directory ([Errno 21] Is a directory), so any path on the host can be probed for existence and readability.

Reaching hosts and ports the account cannot reach

-r also accepts a URL. pip fetches it with an ordinary GET from the server's network position and reflects the first unparsable line of the response body the same way. A response whose body is a single line comes back in full. In a deployment where the single-user server sits inside a private network, this reaches internal services and cloud instance metadata endpoints that the user has no other route to.

Writing files

--log=<path> makes pip create that file if it is absent and append its own log to it otherwise. The content is pip's log text, not text the requester chooses, so the effect is to create files at chosen paths and to corrupt a file that has to parse, such as a configuration file read at the next start.

What this does not add

The same endpoint already uninstalls any installed package when it is given an ordinary, valid package name, so the injection adds no availability impact beyond what the extension manager already permits. Deployments that treat that as unacceptable should use the read-only extension manager, as described below.

pip refuses --python after a subcommand name, and ignores editable entries in an uninstall requirements file, so neither gives code execution.

Patches

JupyterLab v4.6.4 and v4.5.11 contain the patch. The uninstall name is now validated as a PyPI package name in both the HTTP handler and PyPIExtensionManager.uninstall, and the pip command line carries an explicit -- before the package operand.

Users of applications that depend on JupyterLab, such as Notebook v7+, should update jupyterlab package too.

Workarounds

Deployments wanting to disable programmatic extension installation and removal entirely can switch to the read-only extension manager:

--LabApp.extension_manager=readonly

or the following traitlet:

c.LabApp.extension_manager = 'readonly'

You can confirm that the read-only manager is in use from GUI:

image

Users lose the ability to install and remove extensions from the Extension Manager; extensions must then be installed by an administrator in the environment.

Note: an egress policy that blocks outbound requests from the single-user server limits the reach of the URL variant, but does not address the file read or the file write.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 4.6.3"
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "jupyterlab"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.6.0"
            },
            {
              "fixed": "4.6.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 4.5.10"
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "jupyterlab"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.0.0"
            },
            {
              "fixed": "4.5.11"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-102904"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209",
      "CWE-88",
      "CWE-918"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-01T15:21:17Z",
    "nvd_published_at": "2026-09-29T21:17:18Z",
    "severity": "MODERATE"
  },
  "details": "JupyterLab\u0027s PyPI extension manager runs `python -m pip uninstall` with the extension name taken from the request body. `ExtensionHandler.post` validates the name for `cmd=install` but not for `cmd=uninstall`, so a name that begins with `-` reaches the command line and pip reads it as an option rather than as a package.\n\n```python\ncmdline = [\n    sys.executable,\n    \"-m\",\n    \"pip\",\n    \"uninstall\",\n    \"--yes\",\n    \"--no-input\",\n    extension,\n]\n```\n\nAn extension name of the form `-r` followed by a path therefore made pip open that path as a requirements file. pip\u0027s parse error quotes the line it could not read and names the file it came from, and JupyterLab returned that error in the response body, so the line reached the requester.\n\nThis has security implications only for deployments that combine all of the following:\n\n- the (default) PyPI Extension Manager enabled, so that uninstall requests reach pip;\n- an authenticated account permitted to call the extension API; and\n- kernels and terminals disabled or delegated to remote hosts (otherwise a user with kernel access can read the same files and make the same outbound requests directly, regardless of this endpoint)\n\nUnlike [GHSA-37w4-hwhx-4rc4](https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4) and [GHSA-89vp-jrxv-24w8](https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-89vp-jrxv-24w8), this does not need an allowlist or blocklist to be configured. The uninstall path never consulted the listing.\n\n### Impact\n\nAn authenticated user gains a read of server-side files and an outbound request from the server, both outside the confinement that the contents root and the disabled kernels were meant to provide. The user cannot choose which line of a file is returned, and cannot write content of their choosing.\n\n#### Reading files the account cannot reach\n\n`-r\u003cpath\u003e` makes pip open the path as a requirements file. The first line that pip cannot parse as a requirement comes back in the response together with the path. Blank lines and `#` comments are skipped. A line that is a valid package name is accepted silently, and the request answers 201 with no message, so a secret made only of letters, digits, dots, hyphens and underscores is not disclosed. One line is returned per request, and the requester cannot select which one.\n\nThe same option distinguishes a missing path (`[Errno 2] No such file or directory`), an unreadable one (`[Errno 13] Permission denied`) and a directory (`[Errno 21] Is a directory`), so any path on the host can be probed for existence and readability.\n\n#### Reaching hosts and ports the account cannot reach\n\n`-r` also accepts a URL. pip fetches it with an ordinary GET from the server\u0027s network position and reflects the first unparsable line of the response body the same way. A response whose body is a single line comes back in full. In a deployment where the single-user server sits inside a private network, this reaches internal services and cloud instance metadata endpoints that the user has no other route to.\n\n#### Writing files\n\n`--log=\u003cpath\u003e` makes pip create that file if it is absent and append its own log to it otherwise. The content is pip\u0027s log text, not text the requester chooses, so the effect is to create files at chosen paths and to corrupt a file that has to parse, such as a configuration file read at the next start.\n\n#### What this does not add\n\nThe same endpoint already uninstalls any installed package when it is given an ordinary, valid package name, so the injection adds no availability impact beyond what the extension manager already permits. Deployments that treat that as unacceptable should use the read-only extension manager, as described below.\n\npip refuses `--python` after a subcommand name, and ignores editable entries in an uninstall requirements file, so neither gives code execution.\n\n### Patches\n\nJupyterLab [`v4.6.4`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4) and [`v4.5.11`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11) contain the patch. The uninstall name is now validated as a PyPI package name in both the HTTP handler and `PyPIExtensionManager.uninstall`, and the pip command line carries an explicit `--` before the package operand.\n\nUsers of applications that depend on JupyterLab, such as Notebook v7+, should update `jupyterlab` package too.\n\n### Workarounds\n\nDeployments wanting to disable programmatic extension installation and removal entirely can switch to the read-only extension manager:\n\n```bash\n--LabApp.extension_manager=readonly\n```\n\nor the following traitlet:\n\n```python\nc.LabApp.extension_manager = \u0027readonly\u0027\n```\n\nYou can confirm that the read-only manager is in use from GUI:\n\n\u003cimg width=\"293\" height=\"293\" alt=\"image\" src=\"https://github.com/user-attachments/assets/8016c809-633e-4ed0-a5bc-6bc4793caa0f\" /\u003e\n\nUsers lose the ability to install and remove extensions from the Extension Manager; extensions must then be installed by an administrator in the environment.\n\nNote: an egress policy that blocks outbound requests from the single-user server limits the reach of the URL variant, but does not address the file read or the file write.",
  "id": "GHSA-3325-v43h-43rv",
  "modified": "2026-10-01T15:21:17Z",
  "published": "2026-10-01T15:21:17Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102904"
    },
    {
      "type": "WEB",
      "url": "https://github.com/jupyterlab/jupyterlab/commit/9e1951e57da499ca66ef5e0caf68e71ad2e3d1a5"
    },
    {
      "type": "WEB",
      "url": "https://github.com/jupyterlab/jupyterlab/commit/a274a8276b9185d03efd4c3c20713d3137ac49e6"
    },
    {
      "type": "WEB",
      "url": "https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/jupyterlab/jupyterlab"
    },
    {
      "type": "WEB",
      "url": "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11"
    },
    {
      "type": "WEB",
      "url": "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs"
}

GHSA-347P-RFHX-H7FF

Vulnerability from github – Published: 2022-05-24 16:57 – Updated: 2022-12-07 21:30
VLAI
Details

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2019-4441"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2019-10-03T14:15:00Z",
    "severity": "MODERATE"
  },
  "details": "IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.",
  "id": "GHSA-347p-rfhx-h7ff",
  "modified": "2022-12-07T21:30:29Z",
  "published": "2022-05-24T16:57:50Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-4441"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/163177"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/959023"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-35HG-HHVC-V35W

Vulnerability from github – Published: 2022-05-24 19:09 – Updated: 2022-05-24 19:09
VLAI
Details

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196341.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-20430"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2021-07-26T12:15:00Z",
    "severity": "MODERATE"
  },
  "details": "IBM i2 Analyst\u0027s Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196341.",
  "id": "GHSA-35hg-hhvc-v35w",
  "modified": "2022-05-24T19:09:13Z",
  "published": "2022-05-24T19:09:13Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20430"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/196341"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/6474861"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}

GHSA-36HQ-V2FC-RPQP

Vulnerability from github – Published: 2023-08-16 15:30 – Updated: 2023-08-16 21:13
VLAI
Summary
Jenkins Folders Plugin information disclosure vulnerability
Details

Jenkins Folders Plugin displays an error message when attempting to access the Scan Organization Folder Log if no logs are available.

In Folders Plugin 6.846.v23698686f0f6 and earlier, this error message includes the absolute path of a log file, exposing information about the Jenkins controller file system.

Folders Plugin 6.848.ve3b_fd7839a_81 does not display the absolute path of a log file in the error message.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.jenkins-ci.plugins:cloudbees-folder"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.848.ve3b"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2023-40338"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209",
      "CWE-532"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-08-16T21:13:57Z",
    "nvd_published_at": "2023-08-16T15:15:11Z",
    "severity": "MODERATE"
  },
  "details": "Jenkins Folders Plugin displays an error message when attempting to access the Scan Organization Folder Log if no logs are available.\n\nIn Folders Plugin 6.846.v23698686f0f6 and earlier, this error message includes the absolute path of a log file, exposing information about the Jenkins controller file system.\n\nFolders Plugin 6.848.ve3b_fd7839a_81 does not display the absolute path of a log file in the error message.",
  "id": "GHSA-36hq-v2fc-rpqp",
  "modified": "2023-08-16T21:13:57Z",
  "published": "2023-08-16T15:30:17Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40338"
    },
    {
      "type": "WEB",
      "url": "https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3109"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2023/08/16/3"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Jenkins Folders Plugin information disclosure vulnerability"
}

GHSA-3728-546X-W527

Vulnerability from github – Published: 2022-05-24 22:28 – Updated: 2022-05-24 22:28
VLAI
Details

Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exploited, could allow kernel pointers and debug messages to leak to userland.

An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2020-27015"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-209"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-10-30T00:15:00Z",
    "severity": "MODERATE"
  },
  "details": "Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure\u00a0vulnerability\u00a0that if exploited, could allow kernel pointers and debug messages\u00a0to leak to userland.\n\n\n\nAn attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.",
  "id": "GHSA-3728-546x-w527",
  "modified": "2022-05-24T22:28:06Z",
  "published": "2022-05-24T22:28:06Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-27015"
    },
    {
      "type": "WEB",
      "url": "https://helpcenter.trendmicro.com/en-us/article/TMKA-09975"
    },
    {
      "type": "WEB",
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-20-1286"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}

Mitigation MIT-39
Implementation
  • Ensure that error messages only contain minimal details that are useful to the intended audience and no one else. The messages need to strike the balance between being too cryptic (which can confuse users) or being too detailed (which may reveal more than intended). The messages should not reveal the methods that were used to determine the error. Attackers can use detailed information to refine or optimize their original attack, thereby increasing their chances of success.
  • If errors must be captured in some detail, record them in log messages, but consider what could occur if the log messages can be viewed by attackers. Highly sensitive information such as passwords should never be saved to log files.
  • Avoid inconsistent messaging that might accidentally tip off an attacker about internal state, such as whether a user account exists or not.
Mitigation
Implementation

Handle exceptions internally and do not display errors containing potentially sensitive information to a user.

Mitigation MIT-33
Implementation

Strategy: Attack Surface Reduction

Use naming conventions and strong types to make it easier to spot when sensitive data is being used. When creating structures, objects, or other complex entities, separate the sensitive and non-sensitive data as much as possible.

Mitigation MIT-40
Implementation Build and Compilation

Strategy: Compilation or Build Hardening

Debugging information should not make its way into a production release.

Mitigation MIT-40
Implementation Build and Compilation

Strategy: Environment Hardening

Debugging information should not make its way into a production release.

Mitigation
System Configuration

Where available, configure the environment to use less verbose error messages. For example, in PHP, disable the display_errors setting during configuration, or at runtime using the error_reporting() function.

Mitigation
System Configuration

Create default error pages or messages that do not leak any information.

CAPEC-215: Fuzzing for application mapping

An attacker sends random, malformed, or otherwise unexpected messages to a target application and observes the application's log or error messages returned. The attacker does not initially know how a target will respond to individual messages but by attempting a large number of message variants they may find a variant that trigger's desired behavior. In this attack, the purpose of the fuzzing is to observe the application's log and error messages, although fuzzing a target can also sometimes cause the target to enter an unstable state, causing a crash.

CAPEC-463: Padding Oracle Crypto Attack

An adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not a padding error happened while decrypting the ciphertext. A target system that leaks this type of information becomes the padding oracle and an adversary is able to make use of that oracle to efficiently decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). In addition to performing decryption, an adversary is also able to produce valid ciphertexts (i.e., perform encryption) by using the padding oracle, all without knowing the encryption key.

CAPEC-54: Query System for Information

An adversary, aware of an application's location (and possibly authorized to use the application), probes an application's structure and evaluates its robustness by submitting requests and examining responses. Often, this is accomplished by sending variants of expected queries in the hope that these modified queries might return information beyond what the expected set of queries would provide.

CAPEC-7: Blind SQL Injection

Blind SQL Injection results from an insufficient mitigation for SQL Injection. Although suppressing database error messages are considered best practice, the suppression alone is not sufficient to prevent SQL Injection. Blind SQL Injection is a form of SQL Injection that overcomes the lack of error messages. Without the error messages that facilitate SQL Injection, the adversary constructs input strings that probe the target through simple Boolean SQL expressions. The adversary can determine if the syntax and structure of the injection was successful based on whether the query was executed or not. Applied iteratively, the adversary determines how and where the target is vulnerable to SQL Injection.