CVE-2021-41808

LOW

M-Files Server < 21.11.10775.0 - Sensitive Information Disclosure in Federated Authentication Logs

Title source: llm
STIX 2.1

Description

In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.

References (2)

Core 2

Scores

CVSS v3 2.0
EPSS 0.0025
EPSS Percentile 15.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
m-files/m-files_server < 21.11.10775.0
Published Jan 18, 2022
Tracked Since Feb 18, 2026