CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 2 of 25
- CVE-2017-5137MEDIUMCVSS 6.2EG 6.22017-02-05
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.
- CVE-2017-5153HIGHCVSS 7.8EG 7.82017-02-13
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure through server log files vulnerability has …
- CVE-2017-5549MEDIUMCVSS 5.5EG 5.52017-02-06
The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain …
- CVE-2017-6139MEDIUMCVSS 5.9EG 5.92017-12-21
In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers running debug mode logging with BIG-IP AP…
- CVE-2017-6165CRITICALCVSS 9.8EG 9.82017-10-20
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeN…
- CVE-2017-6709CRITICALCVSS 9.8EG 9.82017-07-06
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in …
- CVE-2017-7214CRITICALCVSS 9.8EG 9.82017-03-21
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information suc…
- CVE-2017-7434CRITICALCVSS 3.3EG 9.82018-03-02
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
- CVE-2017-7550CRITICALCVSS 9.8EG 9.82017-11-21
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This f…
- CVE-2017-8001HIGHCVSS 8.4EG 8.42017-11-28
An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentia…
- CVE-2017-8074CRITICALCVSS 9.8EG 9.82017-04-23
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
- CVE-2017-8075CRITICALCVSS 9.8EG 9.82017-04-23
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
- CVE-2017-9271LOWCVSS 3.3EG 3.32018-03-01
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
- CVE-2017-9278CRITICALCVSS 3.3EG 9.82018-03-02
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
- CVE-2017-9615CRITICALCVSS 9.8EG 9.82017-06-26
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.
- CVE-2018-0042CRITICALCVSS 9.8EG 9.82018-07-11
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
- CVE-2018-0335HIGHCVSS 7.8EG 7.82018-06-07
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. …
- CVE-2018-0504MEDIUMCVSS 6.5EG 6.52018-10-04
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
- CVE-2018-1000018HIGHCVSS 7.8EG 7.82018-01-24
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
- CVE-2018-1000060CRITICALCVSS 9.8EG 9.82018-02-09
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data (e.g. passwords) m…
- CVE-2018-1000089HIGHCVSS 7.4EG 7.42018-03-13
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This at…
- CVE-2018-1000123CRITICALCVSS 9.8EG 9.82018-03-13
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other …
- CVE-2018-1072CRITICALCVSS 5.0EG 9.82018-06-26
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing t…
- CVE-2018-1075HIGHCVSS 5.0EG 7.82018-06-12
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input…
- CVE-2018-10855MEDIUMCVSS 5.9EG 5.92018-07-03
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfull…
- CVE-2018-10889MEDIUMCVSS 4.3EG 4.32018-07-10
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.
- CVE-2018-1117CRITICALCVSS 5.0EG 9.82018-06-20
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an e…
- CVE-2018-11320CRITICALCVSS 9.8EG 9.82018-05-21
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.
- CVE-2018-11716CRITICALCVSS 9.8EG 9.82018-07-16
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enro…
- CVE-2018-11717CRITICALCVSS 9.8EG 9.82018-07-16
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accoun…
- CVE-2018-1198HIGHCVSS 8.8EG 8.82018-09-17
Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password.
- CVE-2018-1223HIGHCVSS 8.8EG 8.82018-09-17
Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate priv…
- CVE-2018-1241HIGHCVSS 8.8EG 8.82018-05-29
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to…
- CVE-2018-12604HIGHCVSS 7.5EG 7.52018-06-20
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
- CVE-2018-1264CRITICALCVSS 9.1EG 9.82018-10-05
Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache VM can read this secret, gaining all privileges held by the L…
- CVE-2018-1349MEDIUMCVSS 2.3EG 5.32018-03-26
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
- CVE-2018-1350MEDIUMCVSS 2.3EG 5.32018-03-26
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
- CVE-2018-14700HIGHCVSS 7.5EG 7.52018-12-03
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter.
- CVE-2018-14995MEDIUMCVSS 4.7EG 4.72018-12-28
The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/release-keys, the ZTE Blade Spark Android device with a build fingerprint of ZTE/Z971/peony:7.1.1/NMF26V/20171129.143111:user…
- CVE-2018-15001MEDIUMCVSS 5.5EG 5.52018-12-28
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported act…
- CVE-2018-15002MEDIUMCVSS 4.7EG 4.72018-12-28
The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone user. The com.qualcomm.qti.modemtestmode …
- CVE-2018-15004MEDIUMCVSS 5.9EG 5.92018-12-28
The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a package name of com.qualcomm.qti.modemtestmode (versionCode=24, versionName=7.0) that conta…
- CVE-2018-15763CRITICALCVSS 9.0EG 9.02018-10-05
Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obtain IaaS credential…
- CVE-2018-15797HIGHCVSS 8.4EG 8.82018-12-05
Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user with access to BOSH …
- CVE-2018-16049CRITICALCVSS 9.8EG 9.82018-10-03
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.
- CVE-2018-16095MEDIUMCVSS 5.9EG 5.92018-11-27
In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.
- CVE-2018-16856MEDIUMCVSS 5.5EG 5.52019-03-26
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information…
- CVE-2018-16859MEDIUMCVSS 4.2EG 4.22018-11-29
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the mach…
- CVE-2018-16889HIGHCVSS 5.5EG 7.52019-01-28
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
- CVE-2018-17447HIGHCVSS 7.5EG 7.52018-10-23
An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →