GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
29 advisories
Filter by severity
Jberet: jberet-core logging database credentials
Moderate
CVE-2024-1102
was published
for
org.jberet:jberet-core
(Maven)
Apr 25, 2024
Quarkus CXF logs passwords and other secrets
Moderate
CVE-2024-9621
was published
for
io.quarkiverse.cxf:quarkus-cxf
(Maven)
Oct 8, 2024
Improper masking of credentials in Jenkins Pipeline Maven Integration Plugin
Moderate
CVE-2023-41934
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
Sep 6, 2023
Elasticsearch Insertion of Sensitive Information into Log File
Moderate
CVE-2023-49921
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jul 26, 2024
Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin
Moderate
CVE-2024-39460
was published
for
org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source
(Maven)
Jun 26, 2024
SonarQube logs sensitive information
Moderate
CVE-2024-38460
was published
for
org.sonarsource.sonarqube:sonar-web
(Maven)
Jun 16, 2024
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Moderate
CVE-2023-50740
was published
for
org.apache.linkis:linkis
(Maven)
Mar 6, 2024
Keycloak leaks sensitive information in logged exceptions
Moderate
CVE-2020-1698
was published
for
org.keycloak:keycloak-core
(Maven)
May 24, 2022
Insertion of Sensitive Information into Log File in Apache Tomcat
Moderate
CVE-2011-2204
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Insertion of Sensitive Information into Log File in OWASP DependencyCheck
Moderate
CVE-2024-23686
was published
for
org.owasp:dependency-check-ant
(Maven)
Jan 20, 2024
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
Moderate
CVE-2019-10343
was published
for
io.jenkins:configuration-as-code
(Maven)
May 24, 2022
Maven Integration Plugin did not mask sensitive values in module build logs
Moderate
CVE-2019-10358
was published
for
org.jenkins-ci.main:maven-plugin
(Maven)
May 24, 2022
Plaintext Storage of a Password in Jenkins Configuration as Code Plugin
Moderate
CVE-2019-10345
was published
for
io.jenkins:configuration-as-code
(Maven)
May 24, 2022
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
Moderate
CVE-2019-10367
was published
for
io.jenkins:configuration-as-code
(Maven)
May 24, 2022
Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs
Moderate
CVE-2023-31417
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 26, 2023
Lightbend Alpakka Kafka logs credentials on debug level
Moderate
CVE-2023-29471
was published
for
com.typesafe.akka:akka-stream-kafka
(Maven)
Apr 27, 2023
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
Moderate
CVE-2023-44483
was published
for
org.apache.santuario:xmlsec
(Maven)
Oct 20, 2023
Jenkins HashiCorp Vault Plugin has improper masking of credentials
Moderate
CVE-2023-33001
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
May 16, 2023
Jenkins Folders Plugin information disclosure vulnerability
Moderate
CVE-2023-40338
was published
for
org.jenkins-ci.plugins:cloudbees-folder
(Maven)
Aug 16, 2023
Jenkins Amazon EC2 Plugin leaked beginning of private key in system log
Moderate
CVE-2019-10364
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
Apache NiFi Insertion of Sensitive Information into Log File
Moderate
CVE-2020-1928
was published
for
org.apache.nifi:nifi-parameter
(Maven)
Jan 6, 2022
ovirt-engine Logs Plaintext Passwords To File
Moderate
CVE-2017-15113
was published
for
org.ovirt.engine.sdk:ovirt-engine-sdk-java
(Maven)
May 13, 2022
•
withdrawn
Wildfly logs plaintext passwords
Moderate
CVE-2020-25640
was published
for
org.wildfly:wildfly-parent
(Maven)
Feb 15, 2022
Veracode Scan Jenkins Plugin vulnerable to information disclosure
Moderate
CVE-2023-25721
was published
for
com.veracode.jenkins:veracode-scan
(Maven)
Mar 28, 2023
Spring Vault vulnerable to insertion of sensitive information into a log file
Moderate
CVE-2023-20859
was published
for
org.springframework.vault:spring-vault-core
(Maven)
Mar 23, 2023
ProTip!
Advisories are also available from the
GraphQL API