CWE-532— Insertion of Sensitive Information into Log File
828 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 1 of 17
- CVE-2012-0814MEDIUMCVSS 6.52012-01-27
The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by read…
- CVE-2012-1156HIGHCVSS 7.5EG 7.52019-11-14
Moodle before 2.2.2 has users' private files included in course backups
- CVE-2013-1771HIGHCVSS 7.5EG 7.52019-11-07
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
- CVE-2014-3536MEDIUMCVSS 5.5EG 5.52019-12-15
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
- CVE-2015-1343LOWCVSS 2.02019-04-22
All versions of unity-scope-gdrive logs search terms to syslog.
- CVE-2016-0898CRITICALCVSS 10.02018-03-29
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.
- CVE-2016-10526HIGHCVSS 8.62018-05-31
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the …
- CVE-2016-10819MEDIUMCVSS 6.5EG 6.52019-08-01
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
- CVE-2017-1198LOWCVSS 3.72019-02-05
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or brows…
- CVE-2017-1480MEDIUMCVSS 4.32018-06-06
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
- CVE-2017-15113HIGHCVSS 7.22018-07-27
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-l…
- CVE-2017-1727MEDIUMCVSS 4.3EG 4.32018-01-04
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.
- CVE-2017-1733MEDIUMCVSS 4.02018-04-04
IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.
- CVE-2017-17675MEDIUMCVSS 5.3EG 5.32021-05-19
BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.
- CVE-2017-1795MEDIUMCVSS 4.42018-07-06
IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.
- CVE-2017-18412LOWCVSS 2.5EG 2.52019-08-02
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
- CVE-2017-18423LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
- CVE-2017-18426LOWCVSS 2.7EG 2.72019-08-02
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
- CVE-2017-2592MEDIUMCVSS 5.92018-05-08
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this fla…
- CVE-2017-2621MEDIUMCVSS 5.52018-07-27
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensit…
- CVE-2017-7434LOWCVSS 3.32018-03-02
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
- CVE-2017-9271LOWCVSS 3.32018-03-01
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
- CVE-2017-9278LOWCVSS 3.32018-03-02
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
- CVE-2018-0042CRITICALCVSS 9.82018-07-11
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
- CVE-2018-0335HIGHCVSS 7.8EG 7.82018-06-07
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. …
- CVE-2018-0504MEDIUMCVSS 6.52018-10-04
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
- CVE-2018-1000018HIGHCVSS 7.82018-01-24
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
- CVE-2018-1000060CRITICALCVSS 9.82018-02-09
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data (e.g. passwords) m…
- CVE-2018-1000089HIGHCVSS 7.42018-03-13
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This at…
- CVE-2018-1000123CRITICALCVSS 9.82018-03-13
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other …
- CVE-2018-1072MEDIUMCVSS 5.02018-06-26
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing t…
- CVE-2018-1075MEDIUMCVSS 5.02018-06-12
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input…
- CVE-2018-10855MEDIUMCVSS 5.92018-07-03
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfull…
- CVE-2018-10889MEDIUMCVSS 4.32018-07-10
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.
- CVE-2018-1117MEDIUMCVSS 5.02018-06-20
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an e…
- CVE-2018-11320CRITICALCVSS 9.82018-05-21
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.
- CVE-2018-11716CRITICALCVSS 9.82018-07-16
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enro…
- CVE-2018-11717CRITICALCVSS 9.82018-07-16
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accoun…
- CVE-2018-1198HIGHCVSS 8.82018-09-17
Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password.
- CVE-2018-1223HIGHCVSS 8.82018-09-17
Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate priv…
- CVE-2018-1241HIGHCVSS 8.82018-05-29
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to…
- CVE-2018-12604HIGHCVSS 7.52018-06-20
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
- CVE-2018-1264CRITICALCVSS 9.12018-10-05
Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache VM can read this secret, gaining all privileges held by the L…
- CVE-2018-1349LOWCVSS 2.32018-03-26
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
- CVE-2018-1350LOWCVSS 2.32018-03-26
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
- CVE-2018-14700HIGHCVSS 7.52018-12-03
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter.
- CVE-2018-14995MEDIUMCVSS 4.72018-12-28
The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/release-keys, the ZTE Blade Spark Android device with a build fingerprint of ZTE/Z971/peony:7.1.1/NMF26V/20171129.143111:user…
- CVE-2018-15001MEDIUMCVSS 5.52018-12-28
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported act…
- CVE-2018-15002MEDIUMCVSS 4.72018-12-28
The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone user. The com.qualcomm.qti.modemtestmode …
- CVE-2018-15004MEDIUMCVSS 5.92018-12-28
The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a package name of com.qualcomm.qti.modemtestmode (versionCode=24, versionName=7.0) that conta…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →