CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 13 of 26
- CVE-2022-45098MEDIUMCVSS 6.1EG 6.12023-02-01
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure. …
- CVE-2021-39246MEDIUMCVSS 6.1EG 6.12021-09-24
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be abl…
- CVE-2021-22929MEDIUMCVSS 6.1EG 6.12021-08-31
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
- CVE-2020-11094MEDIUMCVSS 6.1EG 6.12020-06-04
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. This presents a problem if the plugin is…
- CVE-2026-40091MEDIUMCVSS 6.0EG 6.02026-04-15
SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log will include the ful…
- CVE-2025-66910MEDIUMCVSS 6.0EG 6.02025-12-19
Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to op…
- CVE-2025-2002MEDIUMCVSS 6.0EG 6.02025-03-12
CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and…
- CVE-2024-6104MEDIUMCVSS 6.0EG 6.02024-06-24
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-…
- CVE-2023-37224MEDIUMCVSS 6.0EG 6.02023-07-14
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files.
- CVE-2026-107783MEDIUMCVSS 5.9EG 5.92026-10-09
Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts. To remediate t…
- CVE-2026-20708MEDIUMCVSS 5.9EG 5.92026-08-11
Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack…
- CVE-2026-7824MEDIUMCVSS 5.9EG 5.92026-05-05
An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files. An attac…
- CVE-2025-57813MEDIUMCVSS 5.9EG 5.92025-08-26
traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, such as OAuth tokens, are recorded in log files when an error occurs during the execution of…
- CVE-2025-24651MEDIUMCVSS 5.9EG 5.92025-04-17
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1…
- CVE-2024-29954MEDIUMCVSS 5.9EG 5.92024-06-26
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for prot…
- CVE-2022-39876MEDIUMCVSS 5.9EG 5.92022-10-07
Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI.
- CVE-2022-34826MEDIUMCVSS 5.9EG 5.92022-07-15
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
- CVE-2018-15004MEDIUMCVSS 5.9EG 5.92018-12-28
The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a package name of com.qualcomm.qti.modemtestmode (versionCode=24, versionName=7.0) that conta…
- CVE-2018-16095MEDIUMCVSS 5.9EG 5.92018-11-27
In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.
- CVE-2018-10855MEDIUMCVSS 5.9EG 5.92018-07-03
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfull…
- CVE-2017-2592MEDIUMCVSS 5.9EG 5.92018-05-08
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this fla…
- CVE-2017-6139MEDIUMCVSS 5.9EG 5.92017-12-21
In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers running debug mode logging with BIG-IP AP…
- CVE-2017-0380MEDIUMCVSS 5.9EG 5.92017-09-18
The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attack…
- CVE-2026-104872MEDIUMCVSS 5.8EG 5.82026-10-02
OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentatio…
- CVE-2026-55102MEDIUMCVSS 5.8EG 5.82026-08-13
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosErro…
- CVE-2026-46467MEDIUMCVSS 5.8EG 5.82026-07-03
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of se…
- CVE-2021-22518MEDIUMCVSS 5.8EG 5.82024-09-12
A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0
- CVE-2023-32468MEDIUMCVSS 5.8EG 5.82023-07-26
Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability. A remote malicious high-privileged user could potentially exploit this vulnerability leading to exposure of this sensi…
- CVE-2021-37861MEDIUMCVSS 5.8EG 5.82021-12-09
Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
- CVE-2026-78242MEDIUMCVSS 5.7EG 5.72026-10-01
Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure. This issue affects Apache API…
- CVE-2026-64800MEDIUMCVSS 5.7EG 5.72026-07-23
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
- CVE-2026-15737MEDIUMCVSS 5.7EG 5.72026-07-16
AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentat…
- CVE-2025-37727MEDIUMCVSS 5.7EG 5.72025-10-10
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operati…
- CVE-2024-11165MEDIUMCVSS 5.7EG 5.72024-11-13
An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. This oversight results in sensitive information leakage within the yb_backup log files, exp…
- CVE-2024-37286MEDIUMCVSS 5.7EG 5.72024-08-03
APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs…
- CVE-2024-28072MEDIUMCVSS 5.7EG 5.72024-05-03
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
- CVE-2024-23448MEDIUMCVSS 5.7EG 5.72024-02-07
An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the …
- CVE-2020-5414MEDIUMCVSS 5.7EG 5.72020-07-31
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware…
- CVE-2026-66068MEDIUMCVSS 5.6EG 5.62026-09-23
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LOG_DEBUG("shutting down Shovel '~ts', ... Shovel state: ~tp", [Name, State]) formats the entire state map. The 'uris' field holds …
- CVE-2026-81530MEDIUMCVSS 5.6EG 5.62026-08-27
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic rep…
- CVE-2025-68919MEDIUMCVSS 5.6EG 5.62025-12-24
Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to po…
- CVE-2023-6814MEDIUMCVSS 5.6EG 5.62024-03-12
Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 1…
- CVE-2025-36133MEDIUMCVSS 5.9EG 5.52025-09-01
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local u…
- CVE-2022-43937MEDIUMCVSS 5.7EG 5.52024-11-21
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a
- CVE-2026-92758MEDIUMCVSS 5.5EG 5.52026-09-17
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
- CVE-2026-81320MEDIUMCVSS 5.5EG 5.52026-09-15
A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and w…
- CVE-2026-84525MEDIUMCVSS 5.5EG 5.52026-09-14
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
- CVE-2026-84513MEDIUMCVSS 5.5EG 5.52026-09-14
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, wa…
- CVE-2026-84527MEDIUMCVSS 5.5EG 5.52026-09-14
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive u…
- CVE-2026-80124MEDIUMCVSS 5.5EG 5.52026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could po…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →