CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 12 of 26
- CVE-2025-4090MEDIUMCVSS 5.3EG 6.52025-04-29
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
- CVE-2022-43954MEDIUMCVSS 4.3EG 6.52023-02-16
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
- CVE-2022-20807MEDIUMCVSS 4.3EG 6.52022-05-27
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive i…
- CVE-2022-20809MEDIUMCVSS 4.3EG 6.52022-05-26
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive i…
- CVE-2022-36321MEDIUMCVSS 4.1EG 6.52022-07-20
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
- CVE-2022-43772MEDIUMCVSS 3.8EG 6.52023-04-03
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs.
- CVE-2026-85417MEDIUMCVSS 6.4EG 6.42026-09-25
Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or suppor…
- CVE-2025-1979MEDIUMCVSS 6.4EG 6.42025-03-06
Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If the redis password is passed as an argument, it will be logge…
- CVE-2024-41824MEDIUMCVSS 6.4EG 6.42024-07-22
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
- CVE-2020-26199MEDIUMCVSS 6.4EG 6.42021-01-05
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple lo…
- CVE-2022-3902MEDIUMCVSS 5.5EG 6.42023-01-26
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask…
- CVE-2026-95815MEDIUMCVSS 6.3EG 6.32026-09-22
OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep…
- CVE-2026-73467MEDIUMCVSS 6.3EG 6.32026-09-15
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
- CVE-2026-73466MEDIUMCVSS 6.3EG 6.32026-09-15
On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit thes…
- CVE-2026-73465MEDIUMCVSS 6.3EG 6.32026-09-15
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To explo…
- CVE-2025-54319MEDIUMCVSS 6.3EG 6.32025-07-20
An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information via system logging information (syslog verbose logging that includes credentials).
- CVE-2025-24389MEDIUMCVSS 6.3EG 6.32025-01-27
Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTR…
- CVE-2024-20491MEDIUMCVSS 6.3EG 6.32024-10-02
A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are record…
- CVE-2024-20490MEDIUMCVSS 6.3EG 6.32024-10-02
A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerab…
- CVE-2024-39532MEDIUMCVSS 6.3EG 6.32024-07-11
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. When another user performs a …
- CVE-2023-4380MEDIUMCVSS 6.3EG 6.32023-10-04
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the los…
- CVE-2023-32491MEDIUMCVSS 6.3EG 6.32023-08-16
Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.
- CVE-2023-25163MEDIUMCVSS 6.3EG 6.32023-02-08
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitization bug which leaks repository access credentials in error messages. These error messages ar…
- CVE-2026-75057MEDIUMCVSS 6.2EG 6.22026-08-17
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
- CVE-2026-9073MEDIUMCVSS 6.2EG 6.22026-06-23
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credenti…
- CVE-2026-20818MEDIUMCVSS 6.2EG 6.22026-01-13
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.
- CVE-2025-59258MEDIUMCVSS 6.2EG 6.22025-10-14
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
- CVE-2025-36050MEDIUMCVSS 6.2EG 6.22025-06-19
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.
- CVE-2025-49009MEDIUMCVSS 6.2EG 6.22025-06-05
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to…
- CVE-2025-48955MEDIUMCVSS 6.2EG 6.22025-06-02
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused …
- CVE-2024-45091MEDIUMCVSS 6.2EG 6.22025-01-21
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
- CVE-2024-42196MEDIUMCVSS 6.2EG 6.22024-12-06
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
- CVE-2024-8365MEDIUMCVSS 6.2EG 6.22024-09-02
Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the pla…
- CVE-2024-27154MEDIUMCVSS 6.2EG 6.22024-06-14
Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.
- CVE-2023-40694MEDIUMCVSS 6.2EG 6.22024-05-07
IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838.
- CVE-2024-25030MEDIUMCVSS 6.2EG 6.22024-04-03
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.
- CVE-2024-22464MEDIUMCVSS 6.2EG 6.22024-02-08
Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vu…
- CVE-2023-25682MEDIUMCVSS 6.2EG 6.22023-11-22
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.
- CVE-2022-43923MEDIUMCVSS 6.2EG 6.22023-02-24
IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.
- CVE-2021-20536MEDIUMCVSS 6.2EG 6.22021-04-26
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
- CVE-2021-22184MEDIUMCVSS 6.2EG 6.22021-03-26
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.
- CVE-2020-6224MEDIUMCVSS 6.2EG 6.22020-04-14
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends reque…
- CVE-2018-1876MEDIUMCVSS 6.2EG 6.22018-11-02
IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.
- CVE-2017-5137MEDIUMCVSS 6.2EG 6.22017-02-05
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.
- CVE-2026-16689MEDIUMCVSS 5.5EG 6.22026-09-04
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of creden…
- CVE-2026-19649MEDIUMCVSS 5.5EG 6.22026-09-04
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of databa…
- CVE-2026-56459MEDIUMCVSS 5.5EG 6.22026-07-09
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user.
- CVE-2026-12086MEDIUMCVSS 5.5EG 6.22026-06-30
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy stores potentially sensitive information in …
- CVE-2019-25683MEDIUMCVSS 5.5EG 6.22026-04-05
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted …
- CVE-2023-30430MEDIUMCVSS 5.5EG 6.22024-06-27
IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace logs. IBM X-Force ID: 252183.
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →