CWE-117
Medium likelihoodImproper Output Neutralization for Logs
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
102 vulnerabilities with CWE-117
CVE-2024-47083
HIGH
Power Platform Terraform Provider <3.0.0 - Info Disclosure
CVSS 7.5
CVE-2024-45808
MEDIUM
Envoy <1.31.2-1.28.7 - Code Injection
CVSS 6.5
CVE-2024-8334
MEDIUM
master-nan Sweet-CMS <5f441e022b8876f07cde709c77b5be6d2f262e3f - In...
CVSS 4.3
CVE-2024-8297
MEDIUM
Kitsada8621 Digital Library Management System <1.0 - Info Disclosure
CVSS 5.3
CVE-2024-23194
LOW
Gallagher Command Centre <9.10.1268 - Info Disclosure
CVSS 3.3
CVE-2024-0095
CRITICAL
NVIDIA Triton Inference Server 20.10-24.05 - Log Injection and Remote Code Execution
CVSS 9.0
CVE-2024-31845
MEDIUM
Italtel Embrace 1.6.4 - Info Disclosure
CVSS 5.3
CVE-2024-25047
HIGH
IBM Cognos Analytics <12.0.2 - Code Injection
CVSS 8.6
CVE-2024-1681
MEDIUM
flask-cors < 4.0.1 - Log Injection via CRLF Sequence in Request Path
CVSS 5.3
CVE-2024-32474
HIGH
Sentry 24.3.0-24.4.1 - Cleartext Password Exposure in Superuser Authentication Logs
CVSS 7.3
CVE-2024-29022
HIGH
Xibo CMS 1.8.0-3.3.9 and 4.0.0-4.0.8 - Stored Cross-Site Scripting via Request Headers
CVSS 8.8
CVE-2024-22356
MEDIUM
IBM App Connect Enterprise <12.0.9.0 - Info Disclosure
CVSS 4.9
CVE-2024-0690
MEDIUM
ansible-core < 2.14.14 - Information Disclosure via ANSIBLE_NO_LOG Bypass
CVSS 5.0
CVE-2024-0987
MEDIUM
Sichuan Yougou Technology KuERP <1.0.4 - Info Disclosure
CVSS 6.3
CVE-2024-22229
LOW
Dell Unity Operating Environment - Authenticated Log Spoofing via Improper Output Encoding
CVSS 3.1
CVE-2023-28952
MEDIUM
IBM Cognos Controller <11.0.0 - Command Injection
CVSS 5.3
CVE-2023-39461
MEDIUM
Triangle MicroWorks SCADA Data Gateway - Code Injection
CVSS 4.4
CVE-2023-6484
MEDIUM
Keycloak < 22.0.9 - Log Injection via WebAuthn Authentication Form
CVSS 5.3
CVE-2023-38020
MEDIUM
IBM SOAR QRadar Plugin App <5.0.3 - Info Disclosure
CVSS 4.3
CVE-2023-7234
MEDIUM
OPCUAServerToolkit - Info Disclosure
CVSS 5.3
CVE-2023-46713
MEDIUM
Fortinet FortiWeb <7.4.0 - Info Disclosure
CVSS 5.3
CVE-2023-6002
MEDIUM
YugabyteDB 2.14.0.0-2.14.13.9 - Cross-Site Scripting via Log Injection
CVSS 6.5
CVE-2023-46322
CRITICAL
iTerm2 < 3.5.0beta12 - OS Command Injection via SSH URL Hostname
CVSS 9.8
CVE-2023-46321
CRITICAL
iTerm2 <3.5.0beta12 - Path Traversal
CVSS 9.8
CVE-2023-4065
MEDIUM
Red Hat AMQ Broker Operator - Info Disclosure
CVSS 5.5
Details
Vulnerabilities
102
Exploit Likelihood
Medium