CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 20 of 24
- CVE-2025-27496LOWCVSS 3.3EG 3.32025-03-13
Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG…
- CVE-2025-27555MEDIUMCVSS 6.5EG 6.52026-02-24
Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, value…
- CVE-2025-30105HIGHCVSS 8.8EG 8.82025-07-30
Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The…
- CVE-2025-30205HIGHCVSS 7.6EG 7.62025-03-24
kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (optional) kanidm patches provided by kandim-provision will cause t…
- CVE-2025-30483MEDIUMCVSS 5.5EG 5.52025-07-15
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…
- CVE-2025-30677MEDIUMCVSS 6.5EG 6.52025-04-09
Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in app…
- CVE-2025-31139MEDIUMCVSS 4.3EG 4.32025-03-27
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
- CVE-2025-31199MEDIUMCVSS 5.5EG 5.52025-05-29
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, visionOS 2.4. An app may be able to access sensitive user data.
- CVE-2025-31213HIGHCVSS 7.6EG 7.62025-05-12
A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to access associated usernames and websites in a user's iCl…
- CVE-2025-31479HIGHCVSS 8.2EG 8.22025-04-02
canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step fails, the exception output may include the…
- CVE-2025-31514LOWCVSS 2.6EG 2.72025-10-14
A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.…
- CVE-2025-31788MEDIUMCVSS 5.3EG 5.32025-04-01
Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects…
- CVE-2025-32016MEDIUMCVSS 4.7EG 4.72025-04-09
Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affec…
- CVE-2025-32054LOWCVSS 3.3EG 3.32025-04-03
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
- CVE-2025-32382LOWCVSS 1.8EG 1.82025-04-10
Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing password to private key or vice versa), Metabase would not al…
- CVE-2025-34183HIGHCVSS 7.5EG 7.52025-09-16
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full aut…
- CVE-2025-34188HIGHCVSS 7.8EG 7.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local logging mechanism. Authentication session tokens…
- CVE-2025-3456LOWCVSS 3.8EG 3.82025-08-25
On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the…
- CVE-2025-36050MEDIUMCVSS 6.2EG 6.22025-06-19
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.
- CVE-2025-36133MEDIUMCVSS 5.9EG 5.52025-09-01
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local u…
- CVE-2025-36144LOWCVSS 3.3EG 3.32025-09-27
IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.
- CVE-2025-36187MEDIUMCVSS 4.4EG 4.42026-03-25
IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
- CVE-2025-36573HIGHCVSS 7.1EG 7.12025-06-12
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this vulnerability, leading to Information disclosure.
- CVE-2025-36599MEDIUMCVSS 4.3EG 4.32025-07-09
Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the dis…
- CVE-2025-37727MEDIUMCVSS 5.7EG 5.72025-10-10
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operati…
- CVE-2025-38745MEDIUMCVSS 4.8EG 4.82025-08-14
Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backup and Restore. A low privileged attacker with remote access could potentially exploit this…
- CVE-2025-3911MEDIUMCVSS 5.2EG 5.22025-04-29
Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read acces…
- CVE-2025-40603MEDIUMCVSS 4.5EG 4.52025-10-31
A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.
- CVE-2025-4090MEDIUMCVSS 5.3EG 6.52025-04-29
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
- CVE-2025-41690HIGHCVSS 7.4EG 7.42025-09-02
A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s event log. This vulnerability could allow the Operator to authenticate as the Maintenance us…
- CVE-2025-4234LOWCVSS 2.4EG 2.42025-09-12
A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating…
- CVE-2025-42935MEDIUMCVSS 4.1EG 4.12025-08-12
The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosur…
- CVE-2025-43225MEDIUMCVSS 5.5EG 5.52025-07-30
A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.
- CVE-2025-43303MEDIUMCVSS 5.5EG 5.52025-09-15
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.
- CVE-2025-43354MEDIUMCVSS 5.5EG 5.52025-09-15
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.
- CVE-2025-43423LOWCVSS 2.0EG 2.02025-11-04
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical access to an unlock…
- CVE-2025-43426MEDIUMCVSS 5.5EG 5.52025-11-04
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2025-43475MEDIUMCVSS 5.5EG 5.52025-12-17
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensitive data.
- CVE-2025-43485MEDIUMCVSS 4.5EG 4.52025-07-23
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the …
- CVE-2025-43508MEDIUMCVSS 5.5EG 5.52026-01-16
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2025-43517LOWCVSS 3.3EG 3.32025-12-12
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access protected user data.
- CVE-2025-43888HIGHCVSS 8.8EG 8.82025-09-10
Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, le…
- CVE-2025-43937MEDIUMCVSS 6.6EG 6.62026-04-16
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclos…
- CVE-2025-46277LOWCVSS 3.3EG 3.32025-12-17
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, watchOS 26.2. An app may be able to access a user’s Safari history.
- CVE-2025-46313MEDIUMCVSS 5.5EG 5.52026-06-11
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2025-46329LOWCVSS 3.3EG 3.32025-04-29
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the c…
- CVE-2025-46432MEDIUMCVSS 4.3EG 4.32025-04-25
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
- CVE-2025-46614LOWCVSS 3.3EG 3.32025-04-28
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.
- CVE-2025-46752MEDIUMCVSS 4.4EG 4.42025-10-16
A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code.
- CVE-2025-46777LOWCVSS 2.3EG 2.32025-05-28
A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →