CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 11 of 24
- CVE-2022-32556HIGHCVSS 7.5EG 7.52022-07-21
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
- CVE-2022-32565HIGHCVSS 7.5EG 7.52022-06-13
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.
- CVE-2022-3293MEDIUMCVSS 3.5EG 4.32022-10-17
Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1
- CVE-2022-33187MEDIUMCVSS 5.5EG 5.52022-12-09
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.
- CVE-2022-33687LOWCVSS 3.3EG 3.32022-07-12
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
- CVE-2022-33688LOWCVSS 3.3EG 3.32022-07-12
Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
- CVE-2022-33693LOWCVSS 2.0EG 2.32022-07-12
Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
- CVE-2022-33697LOWCVSS 3.3EG 3.32022-07-12
Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
- CVE-2022-33737HIGHCVSS 7.5EG 7.52022-07-06
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password
- CVE-2022-33878MEDIUMCVSS 2.2EG 5.52022-11-02
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a lo…
- CVE-2022-33911MEDIUMCVSS 5.3EG 5.32022-07-12
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
- CVE-2022-34369HIGHCVSS 8.1EG 8.12022-09-02
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vu…
- CVE-2022-34570HIGHCVSS 7.5EG 7.52022-07-25
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.
- CVE-2022-34826MEDIUMCVSS 5.9EG 5.92022-07-15
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
- CVE-2022-3499MEDIUMCVSS 6.5EG 6.52022-10-31
An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of agent logs and data is present.
- CVE-2022-35202MEDIUMCVSS 5.1EG 5.12025-02-11
A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used for signing SAML Authn requests. The underlying issue is a Java keystore that may…
- CVE-2022-35719MEDIUMCVSS 5.1EG 5.52022-11-14
IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.
- CVE-2022-36321MEDIUMCVSS 4.1EG 6.52022-07-20
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
- CVE-2022-36407CRITICALCVSS 9.9EG 9.92024-03-25
Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Storage Platform VP9500, Hitachi Virtual Storage Platform G1000, G1500, Hitachi Virtual Storage Platform F1500, Hitachi Vir…
- CVE-2022-36877LOWCVSS 2.8EG 3.32022-09-09
Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.
- CVE-2022-3691HIGHCVSS 7.5EG 7.52022-11-21
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- CVE-2022-38133MEDIUMCVSS 3.2EG 5.32022-08-10
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
- CVE-2022-38149HIGHCVSS 7.5EG 7.52022-08-17
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.2…
- CVE-2022-38756MEDIUMCVSS 4.3EG 4.32022-12-16
A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by…
- CVE-2022-3902MEDIUMCVSS 5.5EG 6.42023-01-26
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask…
- CVE-2022-39043LOWCVSS 2.4EG 2.42023-03-27
Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physical attacker can access these files to acquire partial user information such as personal contacts.
- CVE-2022-39046HIGHCVSS 7.5EG 7.52022-08-31
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially reve…
- CVE-2022-39821HIGHCVSS 7.5EG 7.52022-09-13
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesyste…
- CVE-2022-39874MEDIUMCVSS 4.0EG 5.52022-10-07
Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
- CVE-2022-39876MEDIUMCVSS 5.9EG 5.92022-10-07
Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI.
- CVE-2022-39893LOWCVSS 3.3EG 3.32022-11-09
Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.
- CVE-2022-39897MEDIUMCVSS 4.4EG 5.52022-12-08
Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.
- CVE-2022-40979MEDIUMCVSS 4.4EG 5.32022-09-23
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
- CVE-2022-41553MEDIUMCVSS 6.5EG 6.52022-11-01
Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allow…
- CVE-2022-41618MEDIUMCVSS 3.7EG 5.32022-11-18
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
- CVE-2022-42439MEDIUMCVSS 6.8EG 6.82023-02-06
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attac…
- CVE-2022-4311MEDIUMCVSS 6.5EG 6.52022-12-12
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect…
- CVE-2022-43673MEDIUMCVSS 4.7EG 4.72022-11-18
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppData\Roaming\Wire\IndexedDB\https_app.wire.com_0.indexeddb.leveldb database.
- CVE-2022-43772MEDIUMCVSS 3.8EG 6.52023-04-03
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs.
- CVE-2022-43870MEDIUMCVSS 6.5EG 6.52023-02-22
IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.
- CVE-2022-43887MEDIUMCVSS 5.3EG 5.32022-12-19
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.…
- CVE-2022-43923MEDIUMCVSS 6.2EG 6.22023-02-24
IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.
- CVE-2022-43930HIGHCVSS 6.2EG 7.52023-02-17
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677.
- CVE-2022-43933MEDIUMCVSS 4.4EG 4.42024-11-21
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. …
- CVE-2022-43935MEDIUMCVSS 5.3EG 4.42024-11-21
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are printed in the embedded MLS DB file.
- CVE-2022-43936MEDIUMCVSS 6.8EG 4.92024-11-21
Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.
- CVE-2022-43937MEDIUMCVSS 5.7EG 5.52024-11-21
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a
- CVE-2022-43954MEDIUMCVSS 4.3EG 6.52023-02-16
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
- CVE-2022-44587MEDIUMCVSS 5.3EG 5.32024-06-21
Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP 2FA: from n/a through 2.6.3.
- CVE-2022-44624HIGHCVSS 6.5EG 7.52022-11-03
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →