CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 2 of 26
- CVE-2025-48709CRITICALCVSS 3.8EG 9.82025-08-07
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when…
- CVE-2017-9278CRITICALCVSS 3.3EG 9.82018-03-02
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
- CVE-2017-7434CRITICALCVSS 3.3EG 9.82018-03-02
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
- CVE-2024-48852CRITICALCVSS 9.4EG 9.42025-01-29
Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through <= 9.3.4.
- CVE-2026-78174CRITICALCVSS 9.3EG 9.32026-08-27
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that admin…
- CVE-2025-7426CRITICALCVSS 9.3EG 9.32025-08-25
Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import stru…
- CVE-2025-54120CRITICALCVSS 9.3EG 9.32025-07-23
PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Altho…
- CVE-2025-22275CRITICALCVSS 9.3EG 9.32025-01-03
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, d…
- CVE-2024-6060CRITICALCVSS 9.3EG 9.32024-06-25
An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.
- CVE-2026-22098CRITICALCVSS 9.2EG 9.22026-07-13
Various sensitive information such as passwords and charging card UIDs are written to log files.
- CVE-2023-36649CRITICALCVSS 9.1EG 9.12023-12-12
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Gran…
- CVE-2023-46668CRITICALCVSS 9.1EG 9.12023-10-26
If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, th…
- CVE-2023-31056CRITICALCVSS 9.1EG 9.12023-04-24
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.
- CVE-2025-63729CRITICALCVSS 9.0EG 9.02025-11-25
An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.
- CVE-2023-31422CRITICALCVSS 9.0EG 9.02023-10-26
An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to …
- CVE-2023-32478CRITICALCVSS 9.0EG 9.02023-07-21
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosur…
- CVE-2022-31098CRITICALCVSS 9.0EG 9.02022-06-27
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to vie…
- CVE-2018-15763CRITICALCVSS 9.0EG 9.02018-10-05
Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obtain IaaS credential…
- CVE-2026-92918HIGHCVSS 8.8EG 8.82026-09-17
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens a…
- CVE-2026-85174HIGHCVSS 8.8EG 8.82026-09-03
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover ad…
- CVE-2026-14948HIGHCVSS 8.8EG 8.82026-08-20
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
- CVE-2026-28923HIGHCVSS 8.8EG 8.82026-05-11
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.
- CVE-2025-43888HIGHCVSS 8.8EG 8.82025-09-10
Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, le…
- CVE-2025-30105HIGHCVSS 8.8EG 8.82025-07-30
Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The…
- CVE-2025-26332HIGHCVSS 8.8EG 8.82025-07-30
TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…
- CVE-2024-27784HIGHCVSS 8.8EG 8.82024-07-09
Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log …
- CVE-2021-39291HIGHCVSS 8.8EG 8.82021-08-23
Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, N…
- CVE-2021-21601HIGHCVSS 8.8EG 8.82021-08-10
Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local low privileged attacker could potentially exploit this vulnerability, leading to the disc…
- CVE-2021-1576HIGHCVSS 8.8EG 8.82021-07-08
Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper autho…
- CVE-2021-3528HIGHCVSS 8.8EG 8.82021-05-13
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use this AuthToken to gai…
- CVE-2020-3281HIGHCVSS 8.8EG 8.82020-06-03
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain…
- CVE-2019-11283HIGHCVSS 8.8EG 8.82019-10-23
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created…
- CVE-2019-3763HIGHCVSS 8.8EG 8.82019-09-11
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability. The Office 365 user password may get logged in a plain text format in the Of…
- CVE-2019-9929HIGHCVSS 8.8EG 8.82019-06-06
Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.
- CVE-2019-9976HIGHCVSS 8.8EG 8.82019-04-11
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users.
- CVE-2019-0029HIGHCVSS 8.8EG 8.82019-01-15
Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credentials an attacker can access the Splunk server. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
- CVE-2018-1223HIGHCVSS 8.8EG 8.82018-09-17
Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate priv…
- CVE-2018-1198HIGHCVSS 8.8EG 8.82018-09-17
Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password.
- CVE-2018-1241HIGHCVSS 8.8EG 8.82018-05-29
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to…
- CVE-2023-22575HIGHCVSS 8.7EG 8.82023-02-01
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalatio…
- CVE-2018-15797HIGHCVSS 8.4EG 8.82018-12-05
Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user with access to BOSH …
- CVE-2021-32570HIGHCVSS 4.9EG 8.82022-08-26
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all mu…
- CVE-2026-40945HIGHCVSS 8.7EG 8.72026-04-21
Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in applicatio…
- CVE-2020-36876HIGHCVSS 8.7EG 8.72025-12-05
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information,…
- CVE-2019-6158HIGHCVSS 8.7EG 8.72019-05-03
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects L…
- CVE-2026-25193HIGHCVSS 8.6EG 8.62026-05-25
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom …
- CVE-2024-29959HIGHCVSS 8.6EG 8.62024-04-19
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.
- CVE-2023-25164HIGHCVSS 8.6EG 8.62023-02-08
Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be…
- CVE-2016-10526HIGHCVSS 8.6EG 8.62018-05-31
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the …
- CVE-2026-12053HIGHCVSS 7.5EG 8.62026-06-25
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insuffi…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →