CWE-117— Improper Output Neutralization for Logs
55 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-117page 1 of 2
- CVE-2015-10011MEDIUMCVSS 4.6EG 9.82023-01-02
A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the file resolverapi/endpoints.py. The manipulation leads to improper output neutralization for logs. The identifier of the pa…
- CVE-2018-10932MEDIUMCVSS 4.32018-08-21
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the te…
- CVE-2019-10213MEDIUMCVSS 6.5EG 3.02019-11-25
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material i…
- CVE-2019-14846HIGHCVSS 7.8EG 7.82019-10-08
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials …
- CVE-2019-14854MEDIUMCVSS 6.5EG 6.52020-01-07
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log leve…
- CVE-2019-14858MEDIUMCVSS 5.5EG 5.52019-10-14
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail…
- CVE-2019-14864MEDIUMCVSS 6.5EG 6.52020-01-02
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors…
- CVE-2020-11644MEDIUMCVSS 6.5EG 6.52020-10-15
The information disclosure vulnerability present in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to generate fake audit log messages.
- CVE-2020-14332MEDIUMCVSS 5.5EG 5.52020-09-11
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The hi…
- CVE-2020-25646HIGHCVSS 7.5EG 7.52020-10-29
A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality
- CVE-2020-4072MEDIUMCVSS 5.3EG 5.32020-06-25
In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to ht…
- CVE-2021-20333MEDIUMCVSS 5.3EG 5.32021-07-23
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior…
- CVE-2021-22096MEDIUMCVSS 4.3EG 4.32021-10-28
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
- CVE-2021-23266MEDIUMCVSS 4.3EG 4.32022-05-16
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
- CVE-2021-42250MEDIUMCVSS 6.5EG 6.52021-11-17
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
- CVE-2021-43410MEDIUMCVSS 5.3EG 5.32021-12-09
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 …
- CVE-2022-1522MEDIUMCVSS 5.3EG 5.32022-09-06
The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Output Neutralization for Logs, which allows an attacker to create false logs that show the password as having been chang…
- CVE-2022-22151HIGHCVSS 8.1EG 8.12022-03-11
CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04…
- CVE-2022-32549MEDIUMCVSS 5.3EG 5.32022-06-22
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
- CVE-2022-4011MEDIUMCVSS 6.5EG 9.82022-11-16
A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutra…
- CVE-2023-0595MEDIUMCVSS 5.3EG 5.32023-02-24
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoSt…
- CVE-2023-1711MEDIUMCVSS 4.0EG 4.02023-05-30
A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information. List of CPEs: * cpe:2.…
- CVE-2023-28952MEDIUMCVSS 5.3EG 5.32024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.
- CVE-2023-31405MEDIUMCVSS 5.3EG 5.32023-07-11
SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interac…
- CVE-2023-32712HIGHCVSS 8.6EG 3.42023-06-01
In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files that, when a vulnerable terminal application reads them, can potenti…
- CVE-2023-36924MEDIUMCVSS 4.9EG 4.92023-07-11
While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the s…
- CVE-2023-36925HIGHCVSS 7.2EG 7.22023-07-11
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the ap…
- CVE-2023-37275LOWCVSS 3.1EG 3.12023-07-13
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GPT command line UI makes heavy use of color-coded print statements to signify different types of system messages to the …
- CVE-2023-38020MEDIUMCVSS 4.3EG 4.32024-02-02
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.
- CVE-2023-39461MEDIUMCVSS 4.4EG 4.42024-05-03
Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to write arbitrary files on affected installations of Triangle MicroWor…
- CVE-2023-3997HIGHCVSS 8.6EG 8.62023-07-31
Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to c…
- CVE-2023-4065MEDIUMCVSS 5.5EG 5.52023-09-27
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of…
- CVE-2023-4571HIGHCVSS 8.6EG 8.62023-08-30
In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Institute (ANSI) escape codes into Splunk ITSI log files that, when a vulnerable terminal app…
- CVE-2023-46321CRITICALCVSS 9.8EG 9.82023-10-23
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.
- CVE-2023-46322CRITICALCVSS 9.8EG 9.82023-10-23
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash,…
- CVE-2023-46713MEDIUMCVSS 5.3EG 5.32023-12-13
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.
- CVE-2023-6002MEDIUMCVSS 6.5EG 7.22023-11-08
YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.
- CVE-2023-6484MEDIUMCVSS 5.3EG 5.32024-04-25
A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.
- CVE-2023-7234MEDIUMCVSS 5.3EG 5.32024-01-16
OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.
- CVE-2024-0095CRITICALCVSS 9.0EG 9.02024-06-13
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead…
- CVE-2024-0690MEDIUMCVSS 5.0EG 5.02024-02-06
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the tas…
- CVE-2024-0987MEDIUMCVSS 6.3EG 6.32024-01-29
A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. The manipulation leads to improper output neutralization for logs. The exploit …
- CVE-2024-1681MEDIUMCVSS 5.3EG 5.32024-04-19
corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. …
- CVE-2024-22229LOWCVSS 3.1EG 3.12024-01-24
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious cont…
- CVE-2024-22356MEDIUMCVSS 4.9EG 4.92024-03-26
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a privileged user. …
- CVE-2024-23194LOWCVSS 3.3EG 3.32024-07-11
Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker limited ability to modify Command Centre log files. This issue affects: Gallagher Command Centre v9.10 prior to vE…
- CVE-2024-25047HIGHCVSS 8.6EG 8.62024-05-02
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 2…
- CVE-2024-29022HIGHCVSS 8.8EG 8.82024-04-12
Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. In affected versions some request headers are not correctly sanitised when stored in the session and display tables. …
- CVE-2024-31845MEDIUMCVSS 5.3EG 5.32024-05-21
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified…
- CVE-2024-32474HIGHCVSS 7.3EG 7.32024-04-18
Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validat…
Map vulnerabilities like CWE-117 to your infrastructure
EchelonGraph correlates every CVE — across CWE-117 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →