In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
References
Configurations
History
23 Feb 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 06:26
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : 1.9
v3 : 2.0 |
| References | () https://www.m-files.com/about/trust-center/security-vulnerabilities/cve-2021-41808/ - Vendor Advisory |
Information
Published : 2022-01-18 17:15
Updated : 2026-02-23 08:16
NVD link : CVE-2021-41808
Mitre link : CVE-2021-41808
CVE.ORG link : CVE-2021-41808
JSON object : View
Products Affected
m-files
- m-files_server
CWE
CWE-532
Insertion of Sensitive Information into Log File
