CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 18 of 24
- CVE-2024-47913MEDIUMCVSS 5.3EG 5.32024-10-04
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not auth…
- CVE-2024-48852CRITICALCVSS 9.4EG 9.42025-01-29
Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through <= 9.3.4.
- CVE-2024-49750MEDIUMCVSS 5.5EG 5.52024-10-24
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, th…
- CVE-2024-49816MEDIUMCVSS 4.9EG 4.92024-12-17
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
- CVE-2024-51528MEDIUMCVSS 4.0EG 4.02024-11-05
Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-51752MEDIUMCVSS 5.5EG 5.52024-11-05
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` f…
- CVE-2024-51753LOWCVSS 2.1EG 2.12024-11-05
The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag,…
- CVE-2024-52009CRITICALCVSS 9.8EG 9.82024-11-08
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs …
- CVE-2024-52067MEDIUMCVSS 4.9EG 4.92024-11-21
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enab…
- CVE-2024-52940HIGHCVSS 7.5EG 7.52024-11-18
AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.
- CVE-2024-54484MEDIUMCVSS 5.5EG 5.52024-12-12
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.
- CVE-2024-54519MEDIUMCVSS 5.5EG 5.52025-01-27
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive location information.
- CVE-2024-5557MEDIUMCVSS 4.5EG 4.52024-06-12
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.
- CVE-2024-55578MEDIUMCVSS 4.3EG 4.32024-12-09
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.
- CVE-2024-55891LOWCVSS 3.1EG 3.12025-01-14
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised …
- CVE-2024-57957MEDIUMCVSS 6.6EG 6.62025-02-06
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-58269MEDIUMCVSS 4.3EG 4.32025-10-29
A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entity with access to Rancher audit logs.
- CVE-2024-5908HIGHCVSS 7.5EG 7.52024-06-12
A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and …
- CVE-2024-6060CRITICALCVSS 9.3EG 9.32024-06-25
An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.
- CVE-2024-6104MEDIUMCVSS 6.0EG 6.02024-06-24
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-…
- CVE-2024-6451HIGHCVSS 7.2EG 7.22024-08-19
AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log t…
- CVE-2024-6687MEDIUMCVSS 5.3EG 5.32024-08-01
The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw directory. The generated .pdf and log files are publicly acc…
- CVE-2024-6977MEDIUMCVSS 6.5EG 6.52024-07-31
A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token…
- CVE-2024-7421MEDIUMCVSS 5.5EG 5.52024-09-25
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launchin…
- CVE-2024-7577MEDIUMCVSS 4.4EG 4.42025-03-29
IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.
- CVE-2024-7586MEDIUMCVSS 4.1EG 4.12025-06-20
An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.
- CVE-2024-8264MEDIUMCVSS 5.5EG 5.52024-10-09
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
- CVE-2024-8365MEDIUMCVSS 6.2EG 6.22024-09-02
Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the pla…
- CVE-2024-8609HIGHCVSS 7.5EG 7.52024-09-27
Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information. This issue affects ValeApp: before v2.0.0.
- CVE-2024-8775MEDIUMCVSS 5.5EG 5.52024-09-14
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without sett…
- CVE-2024-9453MEDIUMCVSS 6.5EG 6.52025-07-04
A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw a…
- CVE-2024-9466MEDIUMCVSS 6.5EG 6.52024-10-09
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.
- CVE-2024-9621MEDIUMCVSS 5.3EG 5.32024-10-08
A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logg…
- CVE-2025-0071MEDIUMCVSS 4.9EG 4.92025-03-11
SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on…
- CVE-2025-0273MEDIUMCVSS 5.5EG 5.52025-03-27
HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.
- CVE-2025-0495MEDIUMCVSS 4.1EG 4.12025-03-17
Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these sec…
- CVE-2025-0736MEDIUMCVSS 5.5EG 5.52025-01-28
A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure c…
- CVE-2025-0976HIGHCVSS 7.5EG 7.52026-02-25
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Mana…
- CVE-2025-10221MEDIUMCVSS 5.5EG 5.52025-09-10
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading …
- CVE-2025-10486MEDIUMCVSS 5.3EG 5.32025-10-15
The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentiall…
- CVE-2025-1053MEDIUMCVSS 4.9EG 4.92025-02-14
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use t…
- CVE-2025-10645MEDIUMCVSS 5.3EG 5.32025-10-07
The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated…
- CVE-2025-1075HIGHCVSS 7.5EG 7.52025-02-19
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache error log file accessible to administrators.
- CVE-2025-11008CRITICALCVSS 9.8EG 9.82025-11-04
The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauthenticated attackers to extract sensitive data including auth…
- CVE-2025-11248LOWCVSS 3.2EG 3.22025-10-27
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.
- CVE-2025-11446MEDIUMCVSS 6.5EG 6.52025-11-19
Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 before 5.2.12.
- CVE-2025-11504HIGHCVSS 7.5EG 7.52025-10-24
The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticate…
- CVE-2025-11547HIGHCVSS 7.8EG 7.82026-02-10
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
- CVE-2025-12940MEDIUMCVSS 5.5EG 5.52025-11-11
Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read …
- CVE-2025-1296MEDIUMCVSS 6.5EG 6.52025-03-10
Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community …
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →