CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 3 of 26
- CVE-2019-1622HIGHCVSS 5.3EG 8.62019-06-27
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improp…
- CVE-2026-82372HIGHCVSS 8.5EG 8.52026-09-24
Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or s…
- CVE-2026-82371HIGHCVSS 8.5EG 8.52026-09-24
Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to…
- CVE-2026-0207HIGHCVSS 8.5EG 8.52026-04-14
A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.
- CVE-2024-42407HIGHCVSS 8.5EG 8.52024-12-12
Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted acce…
- CVE-2026-16528HIGHCVSS 8.4EG 8.42026-10-07
Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security…
- CVE-2026-14443HIGHCVSS 8.4EG 8.42026-09-24
Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archiv…
- CVE-2023-22649HIGHCVSS 8.4EG 8.42024-10-16
A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt…
- CVE-2021-44862HIGHCVSS 8.4EG 8.42022-11-03
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not mask…
- CVE-2017-8001HIGHCVSS 8.4EG 8.42017-11-28
An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentia…
- CVE-2020-35234HIGHCVSS 7.5EG 8.42020-12-14
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file …
- CVE-2026-4788HIGHCVSS 5.5EG 8.42026-04-08
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user.
- CVE-2023-46672HIGHCVSS 5.5EG 8.42023-11-15
An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for the manifestation of this issue are: * Logstash is configured to log in JSON format htt…
- CVE-2024-30151HIGHCVSS 8.3EG 8.32026-05-06
HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing intended access restrictions. This may res…
- CVE-2023-43261HIGHCVSS 7.5EG 8.32023-10-04
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
- CVE-2026-50205HIGHCVSS 8.2EG 8.22026-06-04
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
- CVE-2025-31479HIGHCVSS 8.2EG 8.22025-04-02
canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step fails, the exception output may include the…
- CVE-2024-43444HIGHCVSS 8.2EG 8.22024-08-26
Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affe…
- CVE-2023-46230HIGHCVSS 8.2EG 8.22024-01-30
In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.
- CVE-2023-3350HIGHCVSS 8.2EG 8.22023-10-03
A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the …
- CVE-2023-3349HIGHCVSS 8.2EG 8.22023-10-03
Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, such as usernames, IP addresses or SQL queries sent to the application. By accessing the U…
- CVE-2021-21558HIGHCVSS 8.2EG 8.22021-06-08
Dell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator of the gstd system may potentially exploit this vulnerability to read LDAP credentials from local l…
- CVE-2026-54652HIGHCVSS 8.1EG 8.12026-07-08
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords a…
- CVE-2026-22038HIGHCVSS 8.1EG 8.12026-02-04
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.46, the AutoGPT platform's Stagehand integration blocks lo…
- CVE-2023-46667HIGHCVSS 8.1EG 8.12023-10-26
An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent p…
- CVE-2023-22574HIGHCVSS 8.1EG 8.12023-02-01
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit …
- CVE-2022-34369HIGHCVSS 8.1EG 8.12022-09-02
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vu…
- CVE-2021-45103HIGHCVSS 8.1EG 8.12022-04-06
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.
- CVE-2021-36278HIGHCVSS 8.1EG 8.12021-08-16
Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSOLE, or ISI_PRIV_SYS_SUPPORT privileges …
- CVE-2019-11336HIGHCVSS 8.1EG 8.12019-05-14
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerabil…
- CVE-2018-19786HIGHCVSS 8.1EG 8.12018-12-05
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
- CVE-2018-3827HIGHCVSS 8.1EG 8.12018-09-19
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.
- CVE-2018-3609HIGHCVSS 8.1EG 8.12018-02-16
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authe…
- CVE-2024-20440HIGHCVSS 7.5EG 8.12024-09-04
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulne…
- CVE-2023-6746HIGHCVSS 5.7EG 8.12023-12-21
An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service that could permit an `adversary in the middle attack` when combined with other phishing techn…
- CVE-2025-23374HIGHCVSS 8.0EG 8.02025-01-30
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploi…
- CVE-2023-28441HIGHCVSS 8.0EG 8.02023-03-24
smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affecte…
- CVE-2023-46675HIGHCVSS 6.5EG 8.02023-12-13
An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug level logging is enabled in Kibana. Elastic has released Kibana 8.11.2 which resolves this…
- CVE-2023-46671HIGHCVSS 6.5EG 8.02023-12-13
An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana 8.11.1 which resolves this issue. The error message recorded in the log may contain accou…
- CVE-2024-25959HIGHCVSS 7.9EG 7.92024-03-28
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive informati…
- CVE-2023-22573HIGHCVSS 7.9EG 7.92023-02-01
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information di…
- CVE-2019-19756HIGHCVSS 7.9EG 7.92020-03-13
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.…
- CVE-2026-94593HIGHCVSS 7.8EG 7.82026-10-02
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database whe…
- CVE-2026-49810HIGHCVSS 7.8EG 7.82026-09-21
Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading …
- CVE-2026-40619HIGHCVSS 7.8EG 7.82026-06-02
A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Ge…
- CVE-2025-11547HIGHCVSS 7.8EG 7.82026-02-10
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
- CVE-2025-34188HIGHCVSS 7.8EG 7.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local logging mechanism. Authentication session tokens…
- CVE-2024-12569HIGHCVSS 7.8EG 7.82024-12-19
Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions.
- CVE-2023-34097HIGHCVSS 7.8EG 7.82023-06-05
hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Attackers with access to read system logs will be able to eleva…
- CVE-2022-0010HIGHCVSS 7.8EG 7.82023-05-22
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a syst…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →