CWE-532— Insertion of Sensitive Information into Log File
1,076 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 7 of 22
- CVE-2021-21561HIGHCVSS 7.8EG 5.52021-11-23
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the …
- CVE-2021-21597HIGHCVSS 7.2EG 7.22021-08-10
Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log …
- CVE-2021-21598LOWCVSS 3.9EG 3.92021-08-10
Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in l…
- CVE-2021-21601HIGHCVSS 8.8EG 8.82021-08-10
Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local low privileged attacker could potentially exploit this vulnerability, leading to the disc…
- CVE-2021-21722MEDIUMCVSS 4.4EG 4.42021-01-14
A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This a…
- CVE-2021-22024HIGHCVSS 7.5EG 7.52021-08-30
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sens…
- CVE-2021-22030MEDIUMCVSS 6.5EG 6.52021-11-19
In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can read sensitive(creden…
- CVE-2021-22133LOWCVSS 2.4EG 2.42021-02-10
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the inf…
- CVE-2021-22143LOWCVSS 2.1EG 2.12023-11-22
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM serve…
- CVE-2021-22184MEDIUMCVSS 6.2EG 5.52021-03-26
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.
- CVE-2021-22219MEDIUMCVSS 4.4EG 4.92021-06-08
All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files …
- CVE-2021-22310MEDIUMCVSS 4.4EG 4.42021-03-22
There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may c…
- CVE-2021-22516HIGHCVSS 7.5EG 7.52021-06-04
Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file.
- CVE-2021-22518MEDIUMCVSS 5.8EG 5.82024-09-12
A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0
- CVE-2021-22533MEDIUMCVSS 6.5EG 6.52024-09-12
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.
- CVE-2021-22929MEDIUMCVSS 6.1EG 6.12021-08-31
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
- CVE-2021-23046MEDIUMCVSS 4.9EG 4.92021-09-14
On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. Note: Software versi…
- CVE-2021-23924HIGHCVSS 7.5EG 7.52021-04-01
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
- CVE-2021-24024MEDIUMCVSS 4.3EG 4.32021-04-12
A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and below may allow a remote authenticated attacker to read other local users' password in log…
- CVE-2021-25009MEDIUMCVSS 5.3EG 5.32022-03-07
The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
- CVE-2021-25284MEDIUMCVSS 4.4EG 4.42021-02-27
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
- CVE-2021-25350LOWCVSS 2.0EG 2.02021-03-25
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.
- CVE-2021-25420MEDIUMCVSS 5.5EG 5.52021-06-11
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
- CVE-2021-25421MEDIUMCVSS 5.5EG 5.52021-06-11
Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
- CVE-2021-25422MEDIUMCVSS 5.5EG 5.52021-06-11
Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
- CVE-2021-25423MEDIUMCVSS 5.5EG 5.52021-06-11
Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone via log.
- CVE-2021-25688MEDIUMCVSS 5.5EG 5.52021-02-11
Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux prior to version 21.01.0 may log parts of a user's password in the application logs.
- CVE-2021-26908LOWCVSS 3.3EG 3.32021-04-23
Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 3…
- CVE-2021-26998MEDIUMCVSS 4.3EG 4.32021-08-06
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with au…
- CVE-2021-26999MEDIUMCVSS 4.3EG 4.32021-08-06
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a f…
- CVE-2021-27019MEDIUMCVSS 4.3EG 4.32021-08-30
PuppetDB logging included potentially sensitive system information.
- CVE-2021-27022MEDIUMCVSS 4.9EG 4.92021-09-07
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
- CVE-2021-27026MEDIUMCVSS 4.4EG 4.42021-11-18
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
- CVE-2021-28131HIGHCVSS 7.5EG 7.52021-07-22
Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's se…
- CVE-2021-29759LOWCVSS 2.3EG 2.32021-07-07
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, and 1.3 could allow a privileged user to obtain sensitive information from internal log files. IBM X-Force ID: 202212.
- CVE-2021-3032MEDIUMCVSS 4.4EG 4.42021-01-13
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logr…
- CVE-2021-3034MEDIUMCVSS 5.1EG 5.12021-03-10
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integra…
- CVE-2021-3036MEDIUMCVSS 4.4EG 4.42021-04-20
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerabilit…
- CVE-2021-3037LOWCVSS 2.3EG 2.32021-04-20
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext user…
- CVE-2021-3039LOWCVSS 3.8EG 3.82021-06-10
An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator …
- CVE-2021-31546MEDIUMCVSS 4.3EG 4.32021-04-22
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppression deletions, which should not have been visible to users with access to view AbuseFilter log data.
- CVE-2021-3167MEDIUMCVSS 6.5EG 6.52021-03-15
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
- CVE-2021-32050MEDIUMCVSS 4.2EG 4.22023-08-29
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related co…
- CVE-2021-32074HIGHCVSS 7.5EG 7.52021-05-07
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.
- CVE-2021-32570MEDIUMCVSS 4.9EG 8.82022-08-26
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all mu…
- CVE-2021-32724CRITICALCVSS 9.9EG 9.92021-09-09
check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https://github.com/marketplace/actions/check-spelling) enabled that triggers on `pull_request_ta…
- CVE-2021-32767MEDIUMCVSS 5.3EG 5.32021-07-20
TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0, user credentials may been logged as plain-text. This occurs when explicitly using log lev…
- CVE-2021-32801MEDIUMCVSS 5.5EG 5.52021-09-07
Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionality. It is recommende…
- CVE-2021-3425MEDIUMCVSS 4.4EG 4.42021-06-01
A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ 7 are vulnerable.
- CVE-2021-3429MEDIUMCVSS 5.5EG 5.52023-04-19
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another u…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →