CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 16 of 24
- CVE-2024-25030MEDIUMCVSS 6.2EG 6.22024-04-03
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.
- CVE-2024-25095HIGHCVSS 7.5EG 7.52024-06-04
Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.
- CVE-2024-25654MEDIUMCVSS 5.5EG 5.52024-03-18
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensit…
- CVE-2024-25923MEDIUMCVSS 5.3EG 5.32024-03-28
Insertion of Sensitive Information into Log File vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.2.7.0.
- CVE-2024-25957MEDIUMCVSS 4.8EG 4.82024-03-26
Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. An authenticated local attacker could potentially exploit this vulnerability, leading to informatio…
- CVE-2024-25959HIGHCVSS 7.9EG 7.92024-03-28
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive informati…
- CVE-2024-27097MEDIUMCVSS 4.3EG 4.32024-03-13
A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting false log entries or corrupt the log file format. This has been fixed in the CKAN …
- CVE-2024-27154MEDIUMCVSS 6.2EG 6.22024-06-14
Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27156MEDIUMCVSS 6.8EG 6.82024-06-14
The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. As for the affected prod…
- CVE-2024-27157MEDIUMCVSS 6.8EG 6.82024-06-14
The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. As for the affected products/models/versions, see the ref…
- CVE-2024-27784HIGHCVSS 8.8EG 8.82024-07-09
Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log …
- CVE-2024-27849LOWCVSS 3.3EG 3.32024-10-28
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be able to read sensitive location information.
- CVE-2024-28072MEDIUMCVSS 5.7EG 5.72024-05-03
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
- CVE-2024-28154MEDIUMCVSS 6.5EG 6.52024-03-06
Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.
- CVE-2024-28186HIGHCVSS 7.1EG 7.12024-03-12
FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes SMTP server credentials used by an organization in the application to users of the app…
- CVE-2024-28236HIGHCVSS 7.7EG 7.72024-03-12
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution combined with insensitive fields like `parameters`, `image` and `entrypoint` to inject secr…
- CVE-2024-2877MEDIUMCVSS 5.5EG 5.52024-04-30
Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext. This…
- CVE-2024-28830LOWCVSS 2.7EG 2.72024-06-26
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <=2.0.0p39 (EOL) causes automation user secrets to be written to audit log files accessible to administrators.
- CVE-2024-29177LOWCVSS 2.7EG 2.72024-06-26
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, l…
- CVE-2024-29945HIGHCVSS 7.2EG 7.22024-03-27
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. This exposure happens when either Splunk Enterprise runs in debug mode or the JsonWebT…
- CVE-2024-29954MEDIUMCVSS 5.9EG 5.92024-06-26
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for prot…
- CVE-2024-29955MEDIUMCVSS 5.0EG 5.02024-04-17
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the …
- CVE-2024-29957HIGHCVSS 7.5EG 7.52024-04-19
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encrypt…
- CVE-2024-29958HIGHCVSS 7.5EG 7.52024-04-19
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an a…
- CVE-2024-29959HIGHCVSS 8.6EG 8.62024-04-19
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.
- CVE-2024-30151HIGHCVSS 8.3EG 8.32026-05-06
HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing intended access restrictions. This may res…
- CVE-2024-30511MEDIUMCVSS 5.3EG 5.32024-03-29
Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.45.1.
- CVE-2024-30514MEDIUMCVSS 5.3EG 5.32024-03-29
Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro – Payfast Gateway Add On: from n/a through 1.4.1.
- CVE-2024-30523MEDIUMCVSS 5.3EG 5.32024-03-31
Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Mailchimp Add On pmpro-mailchimp.This issue affects Paid Memberships Pro – Mailchimp Add On: from n/a through 2.3.4.
- CVE-2024-31216MEDIUMCVSS 5.1EG 5.12024-05-15
The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and…
- CVE-2024-31245MEDIUMCVSS 5.3EG 5.32024-04-10
Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.
- CVE-2024-31247MEDIUMCVSS 5.3EG 5.32024-04-10
Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Drupal to WordPress.This issue affects FG Drupal to WordPress: from n/a through 3.70.3.
- CVE-2024-31249MEDIUMCVSS 5.3EG 5.32024-04-10
Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
- CVE-2024-31254LOWCVSS 3.7EG 3.72024-04-10
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.
- CVE-2024-31259HIGHCVSS 7.5EG 7.52024-04-10
Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5.
- CVE-2024-31298MEDIUMCVSS 5.3EG 5.32024-04-10
Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.
- CVE-2024-31353MEDIUMCVSS 5.3EG 5.32024-04-10
Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.
- CVE-2024-31391MEDIUMCVSS 6.5EG 6.52024-04-12
Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will en…
- CVE-2024-3165MEDIUMCVSS 4.5EG 4.52024-04-01
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by…
- CVE-2024-32051MEDIUMCVSS 6.5EG 6.52024-04-24
Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may obtain sensitive information.
- CVE-2024-32513MEDIUMCVSS 5.3EG 5.32024-04-17
Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.3.1.
- CVE-2024-32686MEDIUMCVSS 5.3EG 5.32024-04-18
Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3.
- CVE-2024-32757MEDIUMCVSS 6.8EG 6.82024-07-02
Under certain circumstances unnecessary user details are provided within system logs
- CVE-2024-32788MEDIUMCVSS 5.3EG 5.32024-04-24
Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a through 4.20.2.
- CVE-2024-32811MEDIUMCVSS 5.3EG 5.32024-06-09
Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affects USPS Shipping for WooCommerce – Live Rates: from n/a through 1.9.4.
- CVE-2024-32953HIGHCVSS 7.5EG 7.52024-04-24
Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
- CVE-2024-33637HIGHCVSS 7.5EG 7.52024-04-29
Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.
- CVE-2024-33922MEDIUMCVSS 5.3EG 5.32024-05-02
Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner.This issue affects WP Media Cleaner: from n/a through 6.7.2.
- CVE-2024-34353MEDIUMCVSS 5.5EG 5.52024-05-14
The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This fa…
- CVE-2024-34527HIGHCVSS 7.5EG 7.52024-05-06
spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged.
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →