EN
en direct
type de faiblesse

CWE-532

9
vulnérabilités suivies
1
critiques
20 août 2026
dernière publication
Éditeurs les plus touchés
cve

Veille des vulnérabilités

identifiantvulnérabilitésévéritépublié
CVE-2026-14163In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.Analyse NVD en cours Élevée CVSS 7.1 20/08 CVE-2026-14948A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.Analyse NVD en cours Élevée CVSS 8.8 20/08 CVE-2019-25766Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.Analyse NVD en cours Élevée CVSS 7.5 19/08 CVE-2020-37267Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure DevOps users should revoke and regenerate credentials if logs may have been exposed.Analyse NVD en cours Élevée CVSS 7.5 19/08 CVE-2026-71845A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API.Redhat Advanced Cluster Management For Kubernetes Élevée CVSS 7.7 11/08 CVE-2026-12947IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.Ibm App Connect Enterprise Élevée CVSS 7.5 30/07 CVE-2026-14528IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.Ibm Websphere Application Server Élevée CVSS 7.5 28/07 CVE-2026-22098Various sensitive information such as passwords and charging card UIDs are written to log files. Critique CVSS 9.2 13/07 CVE-2026-54652Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request query strings and enabling viewer-to-admin privilege escalation. A fixed release has not been identified. Élevée CVSS 8.1 08/07

Tapez au moins deux caractères.

naviguer ouvrir esc fermer