CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 6 of 26
- CVE-2023-44155HIGHCVSS 7.5EG 7.52023-09-27
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- CVE-2023-41308HIGHCVSS 7.5EG 7.52023-09-27
Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2023-4108HIGHCVSS 7.5EG 7.52023-08-11
Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged
- CVE-2023-35695HIGHCVSS 7.5EG 7.52023-06-26
A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product.
- CVE-2023-33001HIGHCVSS 7.5EG 7.52023-05-16
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
- CVE-2023-22362HIGHCVSS 7.5EG 7.52023-02-13
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ve…
- CVE-2021-36544HIGHCVSS 7.5EG 7.52023-02-03
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.
- CVE-2022-2721HIGHCVSS 7.5EG 7.52022-11-25
In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled.
- CVE-2022-3691HIGHCVSS 7.5EG 7.52022-11-21
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- CVE-2022-39821HIGHCVSS 7.5EG 7.52022-09-13
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesyste…
- CVE-2022-39046HIGHCVSS 7.5EG 7.52022-08-31
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially reve…
- CVE-2022-38149HIGHCVSS 7.5EG 7.52022-08-17
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.2…
- CVE-2022-34570HIGHCVSS 7.5EG 7.52022-07-25
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.
- CVE-2022-32556HIGHCVSS 7.5EG 7.52022-07-21
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
- CVE-2022-23141HIGHCVSS 7.5EG 7.52022-07-15
ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive info…
- CVE-2022-33737HIGHCVSS 7.5EG 7.52022-07-06
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password
- CVE-2022-32565HIGHCVSS 7.5EG 7.52022-06-13
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.
- CVE-2022-27442HIGHCVSS 7.5EG 7.52022-04-04
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
- CVE-2022-24758HIGHCVSS 7.5EG 7.52022-03-31
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other …
- CVE-2022-27192HIGHCVSS 7.5EG 7.52022-03-23
The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.
- CVE-2022-24757HIGHCVSS 7.5EG 7.52022-03-23
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is…
- CVE-2022-0725HIGHCVSS 7.5EG 7.52022-03-10
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.
- CVE-2022-25374HIGHCVSS 7.5EG 7.52022-02-25
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
- CVE-2021-45034HIGHCVSS 7.5EG 7.52022-01-11
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODU…
- CVE-2021-34797HIGHCVSS 7.5EG 7.52022-01-04
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the pr…
- CVE-2021-34800HIGHCVSS 7.5EG 7.52021-11-29
Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147
- CVE-2021-38283HIGHCVSS 7.5EG 7.52021-11-29
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.
- CVE-2021-20129HIGHCVSS 7.5EG 7.52021-10-13
An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
- CVE-2021-22024HIGHCVSS 7.5EG 7.52021-08-30
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sens…
- CVE-2021-28131HIGHCVSS 7.5EG 7.52021-07-22
Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's se…
- CVE-2020-21933HIGHCVSS 7.5EG 7.52021-07-21
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
- CVE-2020-23284HIGHCVSS 7.5EG 7.52021-07-20
Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database which reveals internal and sensitive information without lo…
- CVE-2021-35299HIGHCVSS 7.5EG 7.52021-06-28
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
- CVE-2020-15380HIGHCVSS 7.5EG 7.52021-06-09
Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.
- CVE-2021-22516HIGHCVSS 7.5EG 7.52021-06-04
Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file.
- CVE-2021-32074HIGHCVSS 7.5EG 7.52021-05-07
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.
- CVE-2021-23924HIGHCVSS 7.5EG 7.52021-04-01
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
- CVE-2020-26605HIGHCVSS 7.5EG 7.52020-10-06
An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attackers to obtain sensitive information by reading a log. The Samsung ID is SVE-2020-18596 (October 2020).
- CVE-2020-25987HIGHCVSS 7.5EG 7.52020-10-06
MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.
- CVE-2020-9486HIGHCVSS 7.5EG 7.52020-10-01
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensit…
- CVE-2020-26106HIGHCVSS 7.5EG 7.52020-09-25
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
- CVE-2020-24566HIGHCVSS 7.5EG 7.52020-09-09
In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under cer…
- CVE-2020-6938HIGHCVSS 7.5EG 7.52020-07-08
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.
- CVE-2019-20852HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).
- CVE-2020-10752HIGHCVSS 7.5EG 7.52020-06-12
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error t…
- CVE-2020-13223HIGHCVSS 7.5EG 7.52020-06-10
HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.
- CVE-2020-13881HIGHCVSS 7.5EG 7.52020-06-06
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
- CVE-2020-13830HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).
- CVE-2020-7654HIGHCVSS 7.5EG 7.52020-05-29
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.
- CVE-2020-11968HIGHCVSS 7.5EG 7.52020-04-21
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced …
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →