CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 7 of 26
- CVE-2020-11605HIGHCVSS 7.5EG 7.52020-04-08
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate in NFC logs. The Samsung ID is SVE-2019-16359 (April 2020).
- CVE-2019-16528HIGHCVSS 7.5EG 7.52020-03-20
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and summaries, from AbuseLog revision data. Thi…
- CVE-2020-1942HIGHCVSS 7.5EG 7.52020-02-11
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flo…
- CVE-2019-16204HIGHCVSS 7.5EG 7.52020-02-05
Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used between the switch and an external server.
- CVE-2019-16203HIGHCVSS 7.5EG 7.52020-02-05
Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configuring the ESRS client.
- CVE-2019-18193HIGHCVSS 7.5EG 7.52020-02-03
In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3.4.109, 4.0.027.13, 4.0.125 and 5.0.013.0.
- CVE-2019-11290HIGHCVSS 7.5EG 7.52019-11-26
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
- CVE-2012-1156HIGHCVSS 7.5EG 7.52019-11-14
Moodle before 2.2.2 has users' private files included in course backups
- CVE-2013-1771HIGHCVSS 7.5EG 7.52019-11-07
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
- CVE-2019-10084HIGHCVSS 7.5EG 7.52019-11-05
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization…
- CVE-2019-18385HIGHCVSS 7.5EG 7.52019-10-23
An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.
- CVE-2019-6656HIGHCVSS 7.5EG 7.52019-09-25
BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-1…
- CVE-2019-0202HIGHCVSS 7.5EG 7.52019-07-26
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not …
- CVE-2019-13509HIGHCVSS 7.5EG 7.52019-07-18
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is r…
- CVE-2019-11492HIGHCVSS 7.5EG 7.52019-04-26
ProjectSend before r1070 writes user passwords to the server logs.
- CVE-2019-9734HIGHCVSS 7.5EG 7.52019-04-24
Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances.
- CVE-2019-9724HIGHCVSS 7.5EG 7.52019-04-24
aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.
- CVE-2018-19513HIGHCVSS 7.5EG 7.52019-03-21
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates explo…
- CVE-2019-0741HIGHCVSS 7.5EG 7.52019-03-05
An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'.
- CVE-2019-0266HIGHCVSS 7.5EG 7.52019-02-15
Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthori…
- CVE-2018-19865HIGHCVSS 7.5EG 7.52018-12-05
A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.
- CVE-2018-14700HIGHCVSS 7.5EG 7.52018-12-03
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter.
- CVE-2018-17447HIGHCVSS 7.5EG 7.52018-10-23
An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
- CVE-2018-3828HIGHCVSS 7.5EG 7.52018-09-19
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers bein…
- CVE-2018-7683HIGHCVSS 7.5EG 7.52018-06-21
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.
- CVE-2018-12604HIGHCVSS 7.5EG 7.52018-06-20
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
- CVE-2018-7204HIGHCVSS 7.5EG 7.52018-03-07
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php con…
- CVE-2018-7433HIGHCVSS 7.5EG 7.52018-03-02
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
- CVE-2017-15572HIGHCVSS 7.5EG 7.52017-10-18
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.
- CVE-2016-6799HIGHCVSS 7.5EG 7.52017-05-09
Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device.…
- CVE-2016-9344HIGHCVSS 7.5EG 7.52017-02-13
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.
- CVE-2016-8346HIGHCVSS 7.5EG 7.52017-02-13
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).
- CVE-2015-8977HIGHCVSS 7.5EG 7.52017-01-31
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
- CVE-2016-9882HIGHCVSS 7.5EG 7.52017-01-13
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs the credentials returned from service brokers in Cloud Controller system component logs. T…
- CVE-2016-0879HIGHCVSS 7.5EG 7.52016-05-31
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspe…
- CVE-2016-0875HIGHCVSS 7.5EG 7.52016-05-31
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.
- CVE-2013-4733HIGHCVSS 7.5EG 7.52013-06-30
The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log file…
- CVE-2026-20239HIGHCVSS 6.5EG 7.52026-05-20
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cooki…
- CVE-2022-44624HIGHCVSS 6.5EG 7.52022-11-03
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
- CVE-2019-6157HIGHCVSS 6.5EG 7.52019-04-22
In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.
- CVE-2022-43930HIGHCVSS 6.2EG 7.52023-02-17
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677.
- CVE-2022-29550HIGHCVSS 5.5EG 7.52022-08-18
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (from environment variables) to disk in cle…
- CVE-2018-16889HIGHCVSS 5.5EG 7.52019-01-28
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
- CVE-2023-0436HIGHCVSS 4.5EG 7.52023-11-07
The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator …
- CVE-2022-4858HIGHCVSS 4.4EG 7.52022-12-30
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
- CVE-2022-32254HIGHCVSS 4.3EG 7.52022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information th…
- CVE-2022-27895HIGHCVSS 4.2EG 7.52022-11-15
Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions earlier than 1.785.0. Upgrade to Build2 version 1.785.0 or g…
- CVE-2022-27896HIGHCVSS 4.2EG 7.52022-11-14
Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python code being run. These service logs included the Foundry toke…
- CVE-2025-41690HIGHCVSS 7.4EG 7.42025-09-02
A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s event log. This vulnerability could allow the Operator to authenticate as the Maintenance us…
- CVE-2018-1000089HIGHCVSS 7.4EG 7.42018-03-13
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This at…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →