CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 21 of 24
- CVE-2025-47979MEDIUMCVSS 5.5EG 5.52025-10-14
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
- CVE-2025-48374MEDIUMCVSS 5.5EG 5.52025-05-22
zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f), when using Keycloak as an oidc provi…
- CVE-2025-48493MEDIUMCVSS 6.5EG 6.52025-06-05
The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text expos…
- CVE-2025-48635HIGHCVSS 7.7EG 7.72026-03-02
In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User …
- CVE-2025-48709CRITICALCVSS 3.8EG 9.82025-08-07
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when…
- CVE-2025-48955MEDIUMCVSS 6.2EG 6.22025-06-02
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused …
- CVE-2025-49009MEDIUMCVSS 6.2EG 6.22025-06-05
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to…
- CVE-2025-49846MEDIUMCVSS 4.1EG 4.12025-07-03
wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view port have been logged to the iOS system logs in clear text. Wire application logs created …
- CVE-2025-50200MEDIUMCVSS 5.5EG 5.52025-06-19
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all…
- CVE-2025-51497MEDIUMCVSS 5.5EG 5.52025-07-17
An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to rea…
- CVE-2025-52580LOWCVSS 2.4EG 2.42025-07-22
Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploited, sensitive user information may be exposed to an attacker who has access to the application logs.
- CVE-2025-52893MEDIUMCVSS 4.5EG 4.52025-06-25
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive information in logs when processing malformed data. This is s…
- CVE-2025-53649MEDIUMCVSS 5.1EG 5.12025-07-29
"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive user information may be exposed to an attacker who ha…
- CVE-2025-53885MEDIUMCVSS 4.2EG 4.22025-07-15
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to co…
- CVE-2025-53886MEDIUMCVSS 4.5EG 4.52025-07-15
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including se…
- CVE-2025-54064MEDIUMCVSS 6.9EG 6.92025-07-17
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. The common Rucio helm-charts for the `rucio-server`, `rucio-ui`, and `rucio-webui` defi…
- CVE-2025-54120CRITICALCVSS 9.3EG 9.32025-07-23
PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Altho…
- CVE-2025-54319MEDIUMCVSS 6.3EG 6.32025-07-20
An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information via system logging information (syslog verbose logging that includes credentials).
- CVE-2025-54376HIGHCVSS 7.5EG 7.52025-09-10
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an una…
- CVE-2025-5463MEDIUMCVSS 5.5EG 5.52025-07-08
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information.
- CVE-2025-5464MEDIUMCVSS 6.5EG 6.52025-07-08
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information.
- CVE-2025-54781LOWCVSS 2.8EG 2.82025-08-02
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau in version 1.0.0, the himmelblaud_tasks service leaks an Intune service access token to the system journal. This shor…
- CVE-2025-54971MEDIUMCVSS 4.3EG 4.32025-11-18
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all versions, FortiADC 6.2 all versions may allow an admin with read…
- CVE-2025-55285LOWCVSS 2.6EG 2.62025-08-15
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets w…
- CVE-2025-5781MEDIUMCVSS 5.2EG 5.22026-02-25
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0…
- CVE-2025-57813MEDIUMCVSS 5.9EG 5.92025-08-26
traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, such as OAuth tokens, are recorded in log files when an error occurs during the execution of…
- CVE-2025-58189MEDIUMCVSS 5.3EG 5.32025-10-29
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
- CVE-2025-59197MEDIUMCVSS 5.5EG 5.52025-10-14
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.
- CVE-2025-59203MEDIUMCVSS 5.5EG 5.52025-10-14
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.
- CVE-2025-59258MEDIUMCVSS 6.2EG 6.22025-10-14
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
- CVE-2025-59355MEDIUMCVSS 6.5EG 6.52026-01-19
A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contai…
- CVE-2025-59868MEDIUMCVSS 5.5EG 5.52026-06-27
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the appli…
- CVE-2025-62208MEDIUMCVSS 5.5EG 5.52025-11-11
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- CVE-2025-62209MEDIUMCVSS 5.5EG 5.52025-11-11
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- CVE-2025-62232HIGHCVSS 7.5EG 7.52025-10-31
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log acces…
- CVE-2025-62262MEDIUMCVSS 4.4EG 4.42025-10-27
Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through upda…
- CVE-2025-62513HIGHCVSS 7.5EG 7.52025-10-22
OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts t…
- CVE-2025-62705MEDIUMCVSS 4.9EG 4.92025-10-22
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes…
- CVE-2025-62879MEDIUMCVSS 4.9EG 4.92026-03-04
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
- CVE-2025-63729CRITICALCVSS 9.0EG 9.02025-11-25
An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.
- CVE-2025-6391CRITICALCVSS 9.1EG 9.82025-07-17
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information…
- CVE-2025-6392MEDIUMCVSS 4.4EG 4.42025-07-10
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not contr…
- CVE-2025-64650MEDIUMCVSS 6.5EG 6.52025-12-08
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.
- CVE-2025-6587MEDIUMCVSS 5.2EG 5.22025-07-03
System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read …
- CVE-2025-66236HIGHCVSS 7.5EG 7.52026-04-13
Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager co…
- CVE-2025-6624HIGHCVSS 7.2EG 7.22025-06-26
Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments …
- CVE-2025-66411MEDIUMCVSS 5.5EG 5.52025-12-03
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limite…
- CVE-2025-66910MEDIUMCVSS 6.0EG 6.02025-12-19
Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to op…
- CVE-2025-6711MEDIUMCVSS 4.9EG 4.92025-07-07
An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 versions prior to 8.0.5, MongoDB Server v…
- CVE-2025-67223HIGHCVSS 7.5EG 7.52026-04-28
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direc…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →