CVE-2020-24566

CVSS v3 Score
7.5
High
CVSS v2 Score
4.3
Medium

Vulnerability Description

In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password is exposed in cleartext in the verbose task logs output.

CVSS:7.5(High)

Moodle before 2.2.2 has users' private files included in course backups

CVSS:7.5(High)

The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.

CVSS:7.5(High)

MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.

CVSS:7.5(High)

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.

CVSS:7.5(High)

Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive informatio...

CVSS:7.5(High)

Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a se...