CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 19 of 24
- CVE-2025-12996MEDIUMCVSS 4.1EG 4.12025-12-04
Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.
- CVE-2025-13321LOWCVSS 3.3EG 3.32025-12-17
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive informati…
- CVE-2025-13611LOWCVSS 2.0EG 2.02025-11-26
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific condit…
- CVE-2025-13743HIGHCVSS 7.5EG 7.52025-12-09
Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occ…
- CVE-2025-13755MEDIUMCVSS 5.5EG 5.52026-05-26
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.
- CVE-2025-13925MEDIUMCVSS 4.9EG 4.92026-01-20
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.
- CVE-2025-14010MEDIUMCVSS 5.5EG 5.52025-12-04
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attacke…
- CVE-2025-14432MEDIUMCVSS 4.9EG 4.92025-12-16
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is …
- CVE-2025-14437HIGHCVSS 7.5EG 7.52025-12-18
The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensi…
- CVE-2025-15332MEDIUMCVSS 4.9EG 4.92026-02-05
Tanium addressed an information disclosure vulnerability in Threat Response.
- CVE-2025-1696MEDIUMCVSS 5.2EG 5.22025-03-06
A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitiv…
- CVE-2025-1979MEDIUMCVSS 6.4EG 6.42025-03-06
Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If the redis password is passed as an argument, it will be logge…
- CVE-2025-1998MEDIUMCVSS 5.5EG 5.52025-03-27
IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores potentially sensitive authentication token information in log files that could …
- CVE-2025-2002MEDIUMCVSS 6.0EG 6.02025-03-12
CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and…
- CVE-2025-20231HIGHCVSS 7.1EG 7.12025-03-26
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Spl…
- CVE-2025-20329MEDIUMCVSS 4.9EG 4.92025-10-15
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploi…
- CVE-2025-20373LOWCVSS 2.7EG 2.72025-11-26
In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new “Data Security Accounts“. The vulnerability would require either local acce…
- CVE-2025-2092HIGHCVSS 7.5EG 7.52025-04-22
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site authentication secrets to be written to log files accessible to administrators.
- CVE-2025-21316MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Kernel Memory Information Disclosure Vulnerability
- CVE-2025-21317MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Kernel Memory Information Disclosure Vulnerability
- CVE-2025-21318MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Kernel Memory Information Disclosure Vulnerability
- CVE-2025-21319MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Kernel Memory Information Disclosure Vulnerability
- CVE-2025-21320MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Kernel Memory Information Disclosure Vulnerability
- CVE-2025-21321MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Kernel Memory Information Disclosure Vulnerability
- CVE-2025-21323MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Kernel Memory Information Disclosure Vulnerability
- CVE-2025-22246LOWCVSS 3.0EG 3.02025-05-13
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
- CVE-2025-22275CRITICALCVSS 9.3EG 9.32025-01-03
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, d…
- CVE-2025-2300MEDIUMCVSS 5.5EG 5.52025-04-22
Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00.
- CVE-2025-23261MEDIUMCVSS 5.5EG 5.52025-09-04
NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disclosing information to unauthorized users.
- CVE-2025-2327MEDIUMCVSS 5.1EG 5.12025-06-16
A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.
- CVE-2025-23289MEDIUMCVSS 5.5EG 5.52025-07-31
NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be written to the log files through proxy servers. A successful exploit of this vulnerability …
- CVE-2025-23374HIGHCVSS 8.0EG 8.02025-01-30
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploi…
- CVE-2025-23413MEDIUMCVSS 4.4EG 4.42025-02-05
When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are no…
- CVE-2025-24034LOWCVSS 3.2EG 3.22025-01-23
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to versions 0.7.15 and 0.8.3, Himmelblau is vulnerable to leaking credentials in debug logs. When debug logging is enabled…
- CVE-2025-24145LOWCVSS 3.3EG 3.32025-01-27
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An app may be able to view a contact's phone number in system logs.
- CVE-2025-24169HIGHCVSS 7.5EG 7.52025-01-27
A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to bypass browser extension authentication.
- CVE-2025-24362HIGHCVSS 7.1EG 7.12025-01-24
In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables from the workflow run, including any secrets that were exposed as environment variables to…
- CVE-2025-24389MEDIUMCVSS 6.3EG 6.32025-01-27
Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTR…
- CVE-2025-24457MEDIUMCVSS 5.5EG 5.52025-01-21
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
- CVE-2025-24520LOWCVSS 3.3EG 3.32025-08-12
Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2514.7.16.0 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2025-24556HIGHCVSS 7.5EG 7.52025-02-03
Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle moowoodle allows Retrieve Embedded Sensitive Data.This issue affects MooWoodle: from n/a through <= 3.2.4.
- CVE-2025-24651MEDIUMCVSS 5.9EG 5.92025-04-17
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1…
- CVE-2025-24884MEDIUMCVSS 5.1EG 5.12025-01-29
kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in t…
- CVE-2025-24984CRITICALCVSS 4.6EG 9.0⚠ KEV2025-03-11
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
- CVE-2025-25002MEDIUMCVSS 6.8EG 6.82025-04-08
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.
- CVE-2025-25013MEDIUMCVSS 6.5EG 6.52025-04-08
Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack.
- CVE-2025-26332HIGHCVSS 8.8EG 8.82025-07-30
TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…
- CVE-2025-26795HIGHCVSS 7.5EG 7.52025-05-14
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2…
- CVE-2025-26864HIGHCVSS 7.5EG 7.52025-05-14
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-bet…
- CVE-2025-27391MEDIUMCVSS 6.5EG 6.52025-04-09
Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug le…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →