CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 12 of 24
- CVE-2022-44745MEDIUMCVSS 5.5EG 5.52022-11-07
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.
- CVE-2022-45098MEDIUMCVSS 6.1EG 6.12023-02-01
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure. …
- CVE-2022-46647LOWCVSS 2.2EG 2.22023-11-14
Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-48228MEDIUMCVSS 5.5EG 5.52023-04-04
An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify and Sentinel Installer log files, aka CORE-7362.
- CVE-2022-48319MEDIUMCVSS 6.5EG 6.52023-02-20
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent …
- CVE-2022-48435LOWCVSS 3.3EG 3.32023-04-04
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
- CVE-2022-4858HIGHCVSS 4.4EG 7.52022-12-30
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
- CVE-2022-49037MEDIUMCVSS 6.5EG 6.52024-09-26
Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote authenticated users to obtain sensitive information via unspecified vectors.
- CVE-2023-0436HIGHCVSS 4.5EG 7.52023-11-07
The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator …
- CVE-2023-0815MEDIUMCVSS 6.8EG 6.82023-02-23
Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridia…
- CVE-2023-1550MEDIUMCVSS 5.5EG 5.52023-03-29
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gai…
- CVE-2023-1786MEDIUMCVSS 5.5EG 5.52023-04-26
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
- CVE-2023-1904MEDIUMCVSS 4.2EG 4.22023-12-14
In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.
- CVE-2023-20207MEDIUMCVSS 4.9EG 4.92023-07-12
A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencr…
- CVE-2023-20859MEDIUMCVSS 5.5EG 5.52023-03-23
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
- CVE-2023-20885MEDIUMCVSS 6.5EG 6.52023-06-16
Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume…
- CVE-2023-20891MEDIUMCVSS 6.5EG 6.52023-07-26
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access …
- CVE-2023-21387MEDIUMCVSS 4.4EG 4.42023-10-30
In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interac…
- CVE-2023-21435MEDIUMCVSS 4.4EG 5.52023-02-09
Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.
- CVE-2023-21492CRITICALCVSS 4.4EG 9.0⚠ KEV2023-05-04
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
- CVE-2023-22362HIGHCVSS 7.5EG 7.52023-02-13
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ve…
- CVE-2023-22447LOWCVSS 2.0EG 2.02023-05-10
Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2023-22481MEDIUMCVSS 4.0EG 4.02023-03-06
FreshRSS is a self-hosted RSS feed aggregator. When using the greader API, the provided password is logged in clear in `users/_/log_api.txt` in the case where the authentication fails. The issues occurs in `authorizationToUser()` in `gread…
- CVE-2023-22572HIGHCVSS 7.8EG 7.82023-02-01
Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeove…
- CVE-2023-22573HIGHCVSS 7.9EG 7.92023-02-01
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information di…
- CVE-2023-22574HIGHCVSS 8.1EG 8.12023-02-01
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit …
- CVE-2023-22575HIGHCVSS 8.7EG 8.82023-02-01
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalatio…
- CVE-2023-22644MEDIUMCVSS 5.5EG 5.52023-09-20
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
- CVE-2023-22649HIGHCVSS 8.4EG 8.42024-10-16
A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt…
- CVE-2023-22733LOWCVSS 2.7EG 2.72023-01-17
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized loggin…
- CVE-2023-22869MEDIUMCVSS 5.5EG 5.52024-04-19
IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.
- CVE-2023-23505LOWCVSS 3.3EG 3.32023-02-27
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, iOS 15.7.3 and iPadOS 15.7.3, iOS 16.3 and iPadOS 16.3…
- CVE-2023-23591MEDIUMCVSS 4.9EG 4.92023-04-12
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
- CVE-2023-24827MEDIUMCVSS 6.5EG 6.52023-02-07
syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure flaw was found in Syft versions v0.69.0 and v0.69.1. This flaw leaks the password stored in…
- CVE-2023-2514MEDIUMCVSS 6.7EG 6.72023-05-12
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization.
- CVE-2023-25163MEDIUMCVSS 6.3EG 6.32023-02-08
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitization bug which leaks repository access credentials in error messages. These error messages ar…
- CVE-2023-25164HIGHCVSS 8.6EG 8.62023-02-08
Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be…
- CVE-2023-25604MEDIUMCVSS 5.5EG 5.52023-10-10
An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords in the RADIUS logs.
- CVE-2023-25682MEDIUMCVSS 6.2EG 6.22023-11-22
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.
- CVE-2023-25687MEDIUMCVSS 4.3EG 4.32023-03-21
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
- CVE-2023-25721MEDIUMCVSS 6.5EG 6.52023-03-28
Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agen…
- CVE-2023-26023MEDIUMCVSS 6.5EG 6.52023-07-19
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
- CVE-2023-26026MEDIUMCVSS 5.3EG 5.32023-07-19
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
- CVE-2023-26207LOWCVSS 3.3EG 3.32023-06-13
An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain passwords in plain text.
- CVE-2023-27502LOWCVSS 3.3EG 3.32024-03-14
Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2316.5.1.2 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2023-28351LOWCVSS 3.3EG 3.32023-05-31
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these …
- CVE-2023-28441HIGHCVSS 8.0EG 8.02023-03-24
smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affecte…
- CVE-2023-28443MEDIUMCVSS 4.2EG 4.22023-03-24
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permiss…
- CVE-2023-28630MEDIUMCVSS 4.2EG 4.22023-03-27
GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environment is not correctly configured by administrators to provide access to the relevant PostgreSQL or MySQL backup tools, t…
- CVE-2023-2878MEDIUMCVSS 6.5EG 6.52023-06-07
Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →