CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

196 vulnerabilities with CWE-359
CVE-2023-42830 LOW
iPadOS < 16.4 - Unauthorized Access to Sensitive Location Information via Log Entries
CVSS 3.3
CVE-2023-50719 HIGH
XWiki Platform 7.2-milestone-2-14.10.14 - Unauthenticated Exposure of Sensitive Information via Solr Search
CVSS 7.5
CVE-2023-25632 MEDIUM
Android Mobile Whale <3.0.1.2 - Auth Bypass
CVSS 5.5
CVE-2023-5983 HIGH
Botanik Software Pharmacy Automation <2.1.133.0 - Info Disclosure
CVSS 7.5
CVE-2023-36052 HIGH
Azure Command-Line Interface < 2.53.1 - Exposure of Private Personal Information via REST Command
CVSS 8.6
CVE-2023-36018 HIGH
Visual Studio Code Jupyter Extension - SSRF
CVSS 7.8
CVE-2023-34085 LOW
PingFederate < 11.3.0 - Unauthorized Exposure of Private User Attributes via DynamoDB Request
CVSS 2.6
CVE-2023-44213 MEDIUM
Acronis Agent < c23.06 - Sensitive Information Disclosure via Excessive System Information Collection
CVSS 5.5
CVE-2023-44156 HIGH
Acronis Cyber Protect 15 < build 35979 - Sensitive Information Disclosure via Spell-Jacking
CVSS 7.5
CVE-2023-1936 LOW
GitLab CE/EE <15.11.10/<16.0.6/<16.1.1 - Info Disclosure
CVSS 3.5
CVE-2023-35151 HIGH
XWiki 7.3-milestone-1-14.4.8 - Unauthenticated Exposure of Obfuscated Passwords via REST Endpoint
CVSS 7.5
CVE-2023-28303 LOW
Microsoft Snip & Sketch/Snipping Tool - Unauthorized Exposure of Private Personal Information
CVSS 3.3
CVE-2023-2703 HIGH
Finex Media Competition Management System < 23.07 - Exposure of Private Personal Information
CVSS 7.5
CVE-2023-22918 MEDIUM
Zyxel ATP/NWA/USG/WAX - Info Disclosure
CVSS 6.5
CVE-2023-2239 MEDIUM
microweber/microweber <1.3.4 - Info Disclosure
CVSS 6.5
CVE-2023-29203 LOW
XWiki 13.9-13.10.8 - Unauthorized Exposure of Private User Information via uorgsuggest.vm
CVSS 3.7
CVE-2023-25819 MEDIUM
Discourse tests-passed and beta branches >= 3.1.0.beta2 - Exposure of Private Personal Information via Metadata
CVSS 5.3
CVE-2023-26041 LOW
Nextcloud Talk <15.0.3 - Info Disclosure
CVSS 2.6
CVE-2022-46168 LOW
Discourse <2.8.14, <2.9.0.beta15 - Info Disclosure
CVSS 3.5
CVE-2022-41971 MEDIUM
Nextcloud Talk 12.0.0-12.2.7 - Unauthorized Video Stream Access After Removal
CVSS 4.8
CVE-2022-41936 MEDIUM
XWiki 8.1-13.10.7 - Unauthorized Exposure of Private Information via Modifications REST Endpoint
CVSS 5.3
CVE-2022-20942 MEDIUM
Cisco AsyncOS < 14.2.1-015 - Authenticated Sensitive Information Exposure via Weak Authorization Checks
CVSS 6.5
CVE-2022-2720 MEDIUM
Octopus Server 3.16.4-2022.1.3154 - Sensitive Value Exposure via Partial Masking Bypass
CVSS 5.3
CVE-2022-36091 HIGH
XWiki Platform <14.2 - Info Disclosure
CVSS 7.5
CVE-2022-0852 MEDIUM
convert2rhel < 0.26 - Unauthorized Password Exposure via Command Line
CVSS 5.5
Details
Vulnerabilities 196