CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 1 of 25
- CVE-2001-1556MEDIUMCVSS v2 5.0EG 5.02001-12-31
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewe…
- CVE-2011-1943LOWCVSS v2 2.1EG 2.12011-06-14
The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive informat…
- CVE-2012-0814MEDIUMCVSS 6.5EG 6.52012-01-27
The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by read…
- CVE-2012-1156HIGHCVSS 7.5EG 7.52019-11-14
Moodle before 2.2.2 has users' private files included in course backups
- CVE-2013-1771HIGHCVSS 7.5EG 7.52019-11-07
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
- CVE-2013-4733HIGHCVSS 7.5EG 7.52013-06-30
The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log file…
- CVE-2013-6384LOWCVSS v2 1.9EG 1.92013-11-23
(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 o…
- CVE-2014-3536MEDIUMCVSS 5.5EG 5.52019-12-15
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
- CVE-2015-1343MEDIUMCVSS 2.0EG 5.32019-04-22
All versions of unity-scope-gdrive logs search terms to syslog.
- CVE-2015-3243MEDIUMCVSS 5.5EG 5.52017-07-25
rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.
- CVE-2015-8977HIGHCVSS 7.5EG 7.52017-01-31
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
- CVE-2016-0296LOWCVSS 3.3EG 3.32017-02-01
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
- CVE-2016-0875HIGHCVSS 7.5EG 7.52016-05-31
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.
- CVE-2016-0879HIGHCVSS 7.5EG 7.52016-05-31
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspe…
- CVE-2016-0898CRITICALCVSS 10.0EG 10.02018-03-29
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.
- CVE-2016-10362MEDIUMCVSS 6.5EG 6.52017-06-16
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
- CVE-2016-10526HIGHCVSS 8.6EG 8.62018-05-31
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the …
- CVE-2016-10819MEDIUMCVSS 6.5EG 6.52019-08-01
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
- CVE-2016-2928MEDIUMCVSS 4.3EG 4.32016-11-25
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.
- CVE-2016-2943LOWCVSS 1.9EG 1.92016-11-30
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.
- CVE-2016-4443MEDIUMCVSS 5.5EG 5.52016-12-14
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
- CVE-2016-5432LOWCVSS 3.3EG 3.32016-10-03
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
- CVE-2016-5967MEDIUMCVSS 5.5EG 5.52016-11-25
The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
- CVE-2016-6799HIGHCVSS 7.5EG 7.52017-05-09
Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device.…
- CVE-2016-8233CRITICALCVSS 9.8EG 9.82017-03-01
Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.
- CVE-2016-8346HIGHCVSS 7.5EG 7.52017-02-13
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).
- CVE-2016-8912MEDIUMCVSS 4.3EG 4.32017-02-01
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.
- CVE-2016-9344HIGHCVSS 7.5EG 7.52017-02-13
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.
- CVE-2016-9882HIGHCVSS 7.5EG 7.52017-01-13
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs the credentials returned from service brokers in Cloud Controller system component logs. T…
- CVE-2016-9985MEDIUMCVSS 5.5EG 5.52017-03-08
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.
- CVE-2017-0380MEDIUMCVSS 5.9EG 5.92017-09-18
The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attack…
- CVE-2017-1000171CRITICALCVSS 9.8EG 9.82017-11-03
Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.
- CVE-2017-11134MEDIUMCVSS 6.5EG 6.52017-08-01
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them.
- CVE-2017-1198MEDIUMCVSS 3.7EG 5.32019-02-05
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or brows…
- CVE-2017-1480MEDIUMCVSS 4.3EG 4.32018-06-06
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
- CVE-2017-15113HIGHCVSS 7.2EG 7.22018-07-27
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-l…
- CVE-2017-15366CRITICALCVSS 9.8EG 9.82017-10-26
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password …
- CVE-2017-15572HIGHCVSS 7.5EG 7.52017-10-18
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.
- CVE-2017-16946MEDIUMCVSS 4.9EG 4.92017-11-25
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
- CVE-2017-1727MEDIUMCVSS 4.3EG 4.32018-01-04
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.
- CVE-2017-1733MEDIUMCVSS 4.0EG 4.02018-04-04
IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.
- CVE-2017-17675MEDIUMCVSS 5.3EG 5.32021-05-19
BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.
- CVE-2017-1795MEDIUMCVSS 4.4EG 4.42018-07-06
IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.
- CVE-2017-18412LOWCVSS 2.5EG 2.52019-08-02
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
- CVE-2017-18423LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
- CVE-2017-18426LOWCVSS 2.7EG 2.72019-08-02
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
- CVE-2017-2592MEDIUMCVSS 5.9EG 5.92018-05-08
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this fla…
- CVE-2017-2621MEDIUMCVSS 5.5EG 5.52018-07-27
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensit…
- CVE-2017-3744MEDIUMCVSS 6.5EG 6.52017-06-20
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Ca…
- CVE-2017-4955CRITICALCVSS 9.8EG 9.82017-06-13
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28, and 1.9.x versions prior to 1.9.5. Several credentials were present in the logs for the …
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →