CVE-2022-0660

CRITICAL Year: 2022
CVSS v3 Score
9.4
Critical
CVSS v2 Score
5.0
Medium

Vulnerability Description

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CVSS:9.1(Critical)

Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVSS:9.1(Critical)

Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12.0, Valinor can use `Throwable#getMessage()` when it should not have permission ...

CVSS:9.8(Critical)

389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.

CVSS:9.8(Critical)

The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts...

CVSS:9.8(Critical)

An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and disp...

CVSS:9.8(Critical)

Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.