CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 10 of 24
- CVE-2022-2394MEDIUMCVSS 4.1EG 4.12022-07-19
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
- CVE-2022-24757HIGHCVSS 7.5EG 7.52022-03-23
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is…
- CVE-2022-24758HIGHCVSS 7.5EG 7.52022-03-31
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other …
- CVE-2022-24875MEDIUMCVSS 5.3EG 5.32022-04-21
The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and including 1.1.1 the `org.conroller.js` code would erroneously log user secrets. This has been resolved in commit `46d98f2b` a…
- CVE-2022-25374HIGHCVSS 7.5EG 7.52022-02-25
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
- CVE-2022-25477MEDIUMCVSS 5.5EG 5.52024-07-02
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode obj…
- CVE-2022-25518MEDIUMCVSS 6.5EG 6.52022-03-22
In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the password of the users who login to the application by querying the database table.
- CVE-2022-25823LOWCVSS 1.9EG 3.32022-03-10
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.
- CVE-2022-25826LOWCVSS 1.9EG 3.32022-03-10
Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log
- CVE-2022-25827LOWCVSS 1.9EG 3.32022-03-10
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log
- CVE-2022-25828LOWCVSS 1.9EG 3.32022-03-10
Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log
- CVE-2022-25829LOWCVSS 1.9EG 3.32022-03-10
Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log
- CVE-2022-25830LOWCVSS 1.9EG 3.32022-03-10
Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log
- CVE-2022-26322MEDIUMCVSS 4.9EG 4.92024-09-12
Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200.
- CVE-2022-26907MEDIUMCVSS 5.3EG 5.32022-04-15
Azure SDK for .NET Information Disclosure Vulnerability
- CVE-2022-27192HIGHCVSS 7.5EG 7.52022-03-23
The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.
- CVE-2022-2721HIGHCVSS 7.5EG 7.52022-11-25
In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled.
- CVE-2022-27442HIGHCVSS 7.5EG 7.52022-04-04
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
- CVE-2022-27549MEDIUMCVSS 4.0EG 5.52022-07-06
HCL Launch may store certain data for recurring activities in a plain text format.
- CVE-2022-27599MEDIUMCVSS 6.7EG 6.72023-09-08
An insertion of sensitive information into Log file vulnerability has been reported to affect product. If exploited, the vulnerability possibly provides local authenticated administrators with an additional, less-protected path to acquirin…
- CVE-2022-27636MEDIUMCVSS 5.5EG 5.52022-05-05
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions…
- CVE-2022-27888MEDIUMCVSS 5.5EG 5.52022-04-26
Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.
- CVE-2022-27893MEDIUMCVSS 4.2EG 4.22022-11-04
The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0.
- CVE-2022-27895HIGHCVSS 4.2EG 7.52022-11-15
Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions earlier than 1.785.0. Upgrade to Build2 version 1.785.0 or g…
- CVE-2022-27896HIGHCVSS 4.2EG 7.52022-11-14
Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python code being run. These service logs included the Foundry toke…
- CVE-2022-28161MEDIUMCVSS 5.5EG 5.52022-05-09
An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authenticated, local attacker to view sensitive information such as ssh passwords in filetansfer.log in debug mode…
- CVE-2022-28625MEDIUMCVSS 5.5EG 5.52022-08-31
A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a co…
- CVE-2022-28774MEDIUMCVSS 5.5EG 5.52022-05-11
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.
- CVE-2022-28859MEDIUMCVSS 6.5EG 6.52022-05-05
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh and nethsm-thales-install.sh) expose the Net HSM partition password. Note: Software versi…
- CVE-2022-29071MEDIUMCVSS 4.0EG 5.52022-08-05
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact…
- CVE-2022-29550HIGHCVSS 5.5EG 7.52022-08-18
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (from environment variables) to disk in cle…
- CVE-2022-29810MEDIUMCVSS 5.5EG 5.52022-04-27
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
- CVE-2022-29869MEDIUMCVSS 5.3EG 5.32022-04-28
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
- CVE-2022-29928MEDIUMCVSS 4.4EG 4.92022-05-12
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
- CVE-2022-30148MEDIUMCVSS 5.5EG 5.52022-06-15
Windows Desired State Configuration (DSC) Information Disclosure Vulnerability
- CVE-2022-3018MEDIUMCVSS 6.8EG 6.82022-10-28
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to acc…
- CVE-2022-30733MEDIUMCVSS 4.0EG 5.32022-06-07
Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.
- CVE-2022-30741LOWCVSS 3.3EG 3.32022-06-07
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log.
- CVE-2022-30742LOWCVSS 3.3EG 3.32022-06-07
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.
- CVE-2022-31047MEDIUMCVSS 5.3EG 5.32022-06-14
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception h…
- CVE-2022-31098CRITICALCVSS 9.0EG 9.02022-06-27
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to vie…
- CVE-2022-31119LOWCVSS 3.1EG 3.12022-08-04
Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail would log user passwords to disk in the event of a misconfiguration. Should an attacker gain access to the logs complete a…
- CVE-2022-31186LOWCVSS 3.3EG 3.32022-08-01
NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulnerability in `next-auth` before `v4.10.2` and `v3.29.9` allows an attacker with log access privilege to obtain excessive …
- CVE-2022-31239MEDIUMCVSS 6.7EG 6.72022-10-21
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this…
- CVE-2022-31674MEDIUMCVSS 4.3EG 4.32022-08-10
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
- CVE-2022-31684MEDIUMCVSS 4.3EG 4.32022-10-19
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTT…
- CVE-2022-3191MEDIUMCVSS 6.6EG 6.62022-11-01
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage Software Agent component) allows local users to gain sensitive information. This issue affects Hitachi Ops Center Analyz…
- CVE-2022-32193MEDIUMCVSS 6.5EG 6.52022-06-13
Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
- CVE-2022-32217MEDIUMCVSS 5.3EG 5.32022-09-23
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs.
- CVE-2022-32254HIGHCVSS 4.3EG 7.52022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information th…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →