CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 8 of 26
- CVE-2025-71425HIGHCVSS 7.3EG 7.32026-09-27
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installati…
- CVE-2025-71423HIGHCVSS 7.3EG 7.32026-09-27
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a …
- CVE-2026-32996HIGHCVSS 7.3EG 7.32026-05-28
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
- CVE-2024-11604HIGHCVSS 7.3EG 7.32026-03-27
Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 bit allows authenticated local users to obtain sensitive information via access to log fil…
- CVE-2026-78627HIGHCVSS 5.5EG 7.32026-09-08
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of w…
- CVE-2026-6720HIGHCVSS 7.2EG 7.22026-05-28
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to ta…
- CVE-2026-20205HIGHCVSS 7.2EG 7.22026-04-15
In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text…
- CVE-2025-6624HIGHCVSS 7.2EG 7.22025-06-26
Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments …
- CVE-2024-6451HIGHCVSS 7.2EG 7.22024-08-19
AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log t…
- CVE-2024-29945HIGHCVSS 7.2EG 7.22024-03-27
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. This exposure happens when either Splunk Enterprise runs in debug mode or the JsonWebT…
- CVE-2023-29002HIGHCVSS 7.2EG 7.22023-04-18
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of the `cilium-secrets` namespace. This could include data such as TLS private keys for Ingress…
- CVE-2021-21597HIGHCVSS 7.2EG 7.22021-08-10
Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log …
- CVE-2017-15113HIGHCVSS 7.2EG 7.22018-07-27
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-l…
- CVE-2023-6802HIGHCVSS 6.5EG 7.22023-12-21
An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could allow an attacker to gain access to the management console. To exploit this, an attacker would need access to t…
- CVE-2026-86049HIGHCVSS 7.1EG 7.12026-09-17
Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for the…
- CVE-2025-36573HIGHCVSS 7.1EG 7.12025-06-12
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this vulnerability, leading to Information disclosure.
- CVE-2025-20231HIGHCVSS 7.1EG 7.12025-03-26
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Spl…
- CVE-2025-24362HIGHCVSS 7.1EG 7.12025-01-24
In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables from the workflow run, including any secrets that were exposed as environment variables to…
- CVE-2024-24272HIGHCVSS 7.1EG 7.12024-03-21
An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of …
- CVE-2024-28186HIGHCVSS 7.1EG 7.12024-03-12
FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes SMTP server credentials used by an organization in the application to users of the app…
- CVE-2020-10750HIGHCVSS 7.1EG 7.12020-06-19
Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. This flaw allows an attacker with access to the container's log file to discover the Kafka…
- CVE-2019-0021HIGHCVSS 7.1EG 7.12019-01-15
On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior …
- CVE-2026-19483HIGHCVSS 5.5EG 7.12026-08-13
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade …
- CVE-2022-20806HIGHCVSS 4.3EG 7.12022-05-27
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive i…
- CVE-2020-10712HIGHCVSS 7.0EG 7.02020-04-22
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage ba…
- CVE-2018-18466HIGHCVSS 7.0EG 7.02019-03-21
An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency credentials in cleartext in the logs (present in the DEBUG folder) that can be accessed by…
- CVE-2026-14442MEDIUMCVSS 6.9EG 6.92026-09-24
An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensi…
- CVE-2025-54064MEDIUMCVSS 6.9EG 6.92025-07-17
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. The common Rucio helm-charts for the `rucio-server`, `rucio-ui`, and `rucio-webui` defi…
- CVE-2026-87672MEDIUMCVSS 6.8EG 6.82026-10-08
An information disclosure vulnerability exists in the SupportLink diagnostic collection utilities of Brocade Fabric OS versions before 10.0.1. When SupportLink is configured to use an authenticated HTTP proxy, the system stores the full pr…
- CVE-2025-46808MEDIUMCVSS 6.8EG 6.82026-09-09
An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
- CVE-2026-58070MEDIUMCVSS 6.8EG 6.82026-08-26
A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.
- CVE-2026-9699MEDIUMCVSS 6.8EG 6.82026-06-26
Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructab…
- CVE-2025-8864MEDIUMCVSS 6.8EG 6.82025-08-11
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs
- CVE-2025-7371MEDIUMCVSS 6.8EG 6.82025-07-22
Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal informatio…
- CVE-2025-25002MEDIUMCVSS 6.8EG 6.82025-04-08
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.
- CVE-2024-32757MEDIUMCVSS 6.8EG 6.82024-07-02
Under certain circumstances unnecessary user details are provided within system logs
- CVE-2024-27157MEDIUMCVSS 6.8EG 6.82024-06-14
The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. As for the affected products/models/versions, see the ref…
- CVE-2024-27156MEDIUMCVSS 6.8EG 6.82024-06-14
The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. As for the affected prod…
- CVE-2024-22440MEDIUMCVSS 6.8EG 6.82024-04-17
A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability could cause disclosure of sensitive information in log files.
- CVE-2023-46231MEDIUMCVSS 6.8EG 6.82024-01-30
In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.
- CVE-2023-31426MEDIUMCVSS 6.8EG 6.82023-08-01
The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to acce…
- CVE-2023-0815MEDIUMCVSS 6.8EG 6.82023-02-23
Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridia…
- CVE-2022-42439MEDIUMCVSS 6.8EG 6.82023-02-06
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attac…
- CVE-2022-3018MEDIUMCVSS 6.8EG 6.82022-10-28
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to acc…
- CVE-2021-43271MEDIUMCVSS 6.8EG 6.82022-06-03
Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when configured to use local, RADIUS, or TACACS authentication) logs usernames and passwords if either is …
- CVE-2020-2004MEDIUMCVSS 6.8EG 6.82020-05-13
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS and Windows. For this…
- CVE-2023-6687MEDIUMCVSS 6.5EG 6.82023-12-12
An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nat…
- CVE-2023-49923MEDIUMCVSS 6.5EG 6.82023-12-12
An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or priva…
- CVE-2026-20144MEDIUMCVSS 4.9EG 6.82026-02-18
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who ho…
- CVE-2026-20142MEDIUMCVSS 4.9EG 6.82026-02-18
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the RSA `accessKey` value from th…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →