The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting fr
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automati
Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticate
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a det
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrar
Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator coul
Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows r
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to e
openssh_key_parser is an open source Python package providing utilities to parse and pack OpenSSH private and public key
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the er
IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a
Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.
Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled.
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a det
A Generation of Error Message Containing Sensitive Information vulnerability in the CLI of Juniper Networks Junos OS all
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before
Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote at
Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnera
When importing resources using Web Workers, error messages would distinguish the difference between <code>application/ja
Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error mess
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library use
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user cre
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacke
Sensitive information could be displayed when a detailed technical error message is posted. This information could discl
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29,
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a re
Sensitive information could be displayed when a detailed technical error message is posted. This information could discl
In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does
The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve info
IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information whe
ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for G
Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through
When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response,
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive infor
Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could pot
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started