CWE-1230Base

Exposure of Sensitive Information Through Metadata

Incomplete in the CWE catalog · 26 CVEs mapped

26
CVEs mapped
5.3
Median CVSS
What it is

The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.

Recent examples
4.3cvss
CVE-2026-14351

CVE-2026-14351 - MEDIUM Severity Vulnerability

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks.

MEDIUMno explanation yet
0%
epss
6.5cvss
CVE-2025-59601

Exposure of Sensitive Information Through Metadata in Powerline Communication Firmware

Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.

MEDIUMno explanation yet
0%
epss
4.3cvss
CVE-2026-45544

Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService

Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1230
Abstraction
Base
Structure
Simple
Status
Incomplete