CVE-2021-41808

LOW

M-files Server < 21.11.10775.0 - Log Information Exposure

Title source: rule
STIX 2.1

Description

In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.

References (2)

Core 2

Scores

CVSS v3 2.0
EPSS 0.0005
EPSS Percentile 14.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
m-files/m-files_server < 21.11.10775.0
Published Jan 18, 2022
Tracked Since Feb 18, 2026