CWE-532— Insertion of Sensitive Information into Log File
1,076 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 5 of 22
- CVE-2020-10712HIGHCVSS 7.0EG 7.02020-04-22
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage ba…
- CVE-2020-10750HIGHCVSS 7.1EG 7.12020-06-19
Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. This flaw allows an attacker with access to the container's log file to discover the Kafka…
- CVE-2020-10752HIGHCVSS 7.5EG 7.52020-06-12
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error t…
- CVE-2020-10762MEDIUMCVSS 5.5EG 5.52020-11-24
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows …
- CVE-2020-10763MEDIUMCVSS 5.5EG 5.52020-11-24
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwo…
- CVE-2020-11094MEDIUMCVSS 6.1EG 6.12020-06-04
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. This presents a problem if the plugin is…
- CVE-2020-11605HIGHCVSS 7.5EG 7.52020-04-08
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate in NFC logs. The Samsung ID is SVE-2019-16359 (April 2020).
- CVE-2020-11643MEDIUMCVSS 6.5EG 6.52020-10-15
An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign domains.
- CVE-2020-11646MEDIUMCVSS 4.3EG 4.32020-10-15
A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view log information reserved for other users.
- CVE-2020-11932LOWCVSS 2.3EG 2.32020-05-13
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.
- CVE-2020-11968HIGHCVSS 7.5EG 7.52020-04-21
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced …
- CVE-2020-12023LOWCVSS 2.0EG 4.52020-06-11
Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge En…
- CVE-2020-13223HIGHCVSS 7.5EG 7.52020-06-10
HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.
- CVE-2020-13830HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).
- CVE-2020-13881HIGHCVSS 7.5EG 7.52020-06-06
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
- CVE-2020-14330MEDIUMCVSS 5.0EG 5.02020-09-11
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to re…
- CVE-2020-14332MEDIUMCVSS 5.5EG 5.52020-09-11
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The hi…
- CVE-2020-14470MEDIUMCVSS 6.5EG 6.52020-06-19
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password.
- CVE-2020-14518MEDIUMCVSS 5.3EG 5.32020-08-21
Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.
- CVE-2020-15095MEDIUMCVSS 4.4EG 4.42020-07-07
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not r…
- CVE-2020-15370MEDIUMCVSS 6.5EG 6.52020-09-25
Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files.
- CVE-2020-15380HIGHCVSS 7.5EG 7.52021-06-09
Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.
- CVE-2020-15581MEDIUMCVSS 5.3EG 5.32020-07-07
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The kernel logging feature allows attackers to discover virtual addresses via vectors involving shared memory. The Samsung ID is SVE-2020-17605 (J…
- CVE-2020-15829MEDIUMCVSS 5.3EG 5.32020-08-08
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
- CVE-2020-1620MEDIUMCVSS 5.5EG 5.52020-04-08
A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- CVE-2020-1621MEDIUMCVSS 5.5EG 5.52020-04-08
A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- CVE-2020-1622MEDIUMCVSS 5.5EG 5.52020-04-08
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
- CVE-2020-1623MEDIUMCVSS 5.5EG 5.52020-04-08
A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to 19.2R1.
- CVE-2020-1624MEDIUMCVSS 5.5EG 5.52020-04-08
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
- CVE-2020-1698MEDIUMCVSS 5.0EG 5.02020-05-11
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
- CVE-2020-1753MEDIUMCVSS 5.0EG 5.02020-03-16
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive par…
- CVE-2020-1928MEDIUMCVSS 5.3EG 5.32020-01-28
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was …
- CVE-2020-1942HIGHCVSS 7.5EG 7.52020-02-11
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flo…
- CVE-2020-1987LOWCVSS 3.9EG 3.92020-04-08
An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump". This issue …
- CVE-2020-2004MEDIUMCVSS 6.8EG 6.82020-05-13
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS and Windows. For this…
- CVE-2020-2043LOWCVSS 3.3EG 3.32020-09-09
An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for confi…
- CVE-2020-2044LOWCVSS 3.3EG 3.32020-09-09
An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was int…
- CVE-2020-2048LOWCVSS 3.3EG 3.32020-11-12
An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This iss…
- CVE-2020-21933HIGHCVSS 7.5EG 7.52021-07-21
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
- CVE-2020-23284HIGHCVSS 7.5EG 7.52021-07-20
Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database which reveals internal and sensitive information without lo…
- CVE-2020-24038MEDIUMCVSS 6.5EG 6.52021-07-07
myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.
- CVE-2020-24566HIGHCVSS 7.5EG 7.52020-09-09
In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under cer…
- CVE-2020-24804MEDIUMCVSS 6.5EG 6.52023-08-11
Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information via audit logs.
- CVE-2020-25046MEDIUMCVSS 5.5EG 5.52020-08-31
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).
- CVE-2020-25640MEDIUMCVSS 5.3EG 5.32020-11-24
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
- CVE-2020-25987HIGHCVSS 7.5EG 7.52020-10-06
MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.
- CVE-2020-26106HIGHCVSS 7.5EG 7.52020-09-25
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
- CVE-2020-26199MEDIUMCVSS 6.4EG 6.42021-01-05
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple lo…
- CVE-2020-26416MEDIUMCVSS 4.0EG 4.02020-12-11
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
- CVE-2020-26605HIGHCVSS 7.5EG 7.52020-10-06
An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attackers to obtain sensitive information by reading a log. The Samsung ID is SVE-2020-18596 (October 2020).
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →