CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 11 of 26
- CVE-2021-3791MEDIUMCVSS 6.5EG 6.52021-11-12
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such a…
- CVE-2021-40352MEDIUMCVSS 6.5EG 6.52021-09-01
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.
- CVE-2021-37709MEDIUMCVSS 6.5EG 6.52021-08-16
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for …
- CVE-2020-24038MEDIUMCVSS 6.5EG 6.52021-07-07
myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.
- CVE-2021-3167MEDIUMCVSS 6.5EG 6.52021-03-15
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
- CVE-2021-20359MEDIUMCVSS 6.5EG 6.52021-02-08
IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in log files that could be obtained by an unauthorized user. IBM X-Force ID: 194966.
- CVE-2020-4671MEDIUMCVSS 6.5EG 6.52020-11-16
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an authenticatedl user. IBM X-Force ID: 186284.
- CVE-2020-11643MEDIUMCVSS 6.5EG 6.52020-10-15
An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign domains.
- CVE-2020-5389MEDIUMCVSS 6.5EG 6.52020-10-08
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vulnerability. Authenticated low privileged OMIMSCC users may be able to retrieve sensitive …
- CVE-2020-15370MEDIUMCVSS 6.5EG 6.52020-09-25
Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files.
- CVE-2020-14470MEDIUMCVSS 6.5EG 6.52020-06-19
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password.
- CVE-2020-4477MEDIUMCVSS 6.5EG 6.52020-06-15
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system. IBM X-Force ID: 181779.
- CVE-2020-7599MEDIUMCVSS 6.5EG 6.52020-03-30
All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with the --info log level flag, the Gradle Logg…
- CVE-2019-16157MEDIUMCVSS 6.5EG 6.52020-03-13
An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug commands.
- CVE-2020-5400MEDIUMCVSS 6.5EG 6.52020-02-27
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to thos…
- CVE-2019-11292MEDIUMCVSS 6.5EG 6.52020-01-09
Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, i…
- CVE-2019-14854MEDIUMCVSS 6.5EG 6.52020-01-07
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log leve…
- CVE-2019-14864MEDIUMCVSS 6.5EG 6.52020-01-02
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors…
- CVE-2019-15235MEDIUMCVSS 6.5EG 6.52019-12-17
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use th…
- CVE-2019-14782MEDIUMCVSS 6.5EG 6.52019-12-17
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp directory, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use them t…
- CVE-2019-10695MEDIUMCVSS 6.5EG 6.52019-12-12
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details pane in the PE console. These issues have been resolved i…
- CVE-2019-11293MEDIUMCVSS 6.5EG 6.52019-12-06
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.…
- CVE-2019-10195MEDIUMCVSS 6.5EG 6.52019-11-27
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear …
- CVE-2019-10213MEDIUMCVSS 6.5EG 6.52019-11-25
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material i…
- CVE-2019-6662MEDIUMCVSS 6.5EG 6.52019-11-15
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.
- CVE-2019-11549MEDIUMCVSS 6.5EG 6.52019-09-09
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are inclu…
- CVE-2019-11250MEDIUMCVSS 6.5EG 6.52019-08-29
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, whic…
- CVE-2019-15508MEDIUMCVSS 6.5EG 6.52019-08-23
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to th…
- CVE-2019-15507MEDIUMCVSS 6.5EG 6.52019-08-23
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to t…
- CVE-2019-5634MEDIUMCVSS 6.5EG 6.52019-08-22
An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetoot…
- CVE-2019-13515MEDIUMCVSS 6.5EG 6.52019-08-15
OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.
- CVE-2019-1953MEDIUMCVSS 6.5EG 6.52019-08-08
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password wh…
- CVE-2019-10370MEDIUMCVSS 6.5EG 6.52019-08-07
Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.
- CVE-2016-10819MEDIUMCVSS 6.5EG 6.52019-08-01
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
- CVE-2019-10358MEDIUMCVSS 6.5EG 6.52019-07-31
Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.
- CVE-2019-14268MEDIUMCVSS 6.5EG 6.52019-07-25
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in …
- CVE-2019-13098MEDIUMCVSS 6.5EG 6.52019-07-22
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on…
- CVE-2018-19583MEDIUMCVSS 6.5EG 6.52019-07-10
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.
- CVE-2019-8944MEDIUMCVSS 6.5EG 6.52019-02-20
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
- CVE-2018-19014MEDIUMCVSS 6.5EG 6.52019-01-28
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an …
- CVE-2018-0504MEDIUMCVSS 6.5EG 6.52018-10-04
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
- CVE-2018-1999036MEDIUMCVSS 6.5EG 6.52018-08-01
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.
- CVE-2018-7682MEDIUMCVSS 6.5EG 6.52018-06-22
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
- CVE-2018-3817MEDIUMCVSS 6.5EG 6.52018-03-30
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
- CVE-2018-2372MEDIUMCVSS 6.5EG 6.52018-02-14
A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.
- CVE-2017-11134MEDIUMCVSS 6.5EG 6.52017-08-01
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them.
- CVE-2017-3744MEDIUMCVSS 6.5EG 6.52017-06-20
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Ca…
- CVE-2016-10362MEDIUMCVSS 6.5EG 6.52017-06-16
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
- CVE-2012-0814MEDIUMCVSS 6.5EG 6.52012-01-27
The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by read…
- CVE-2021-36718MEDIUMCVSS 6.1EG 6.52021-12-08
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has b…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →