CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 9 of 24
- CVE-2021-3684MEDIUMCVSS 5.5EG 5.52023-03-24
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull se…
- CVE-2021-37036MEDIUMCVSS 5.5EG 5.52021-11-23
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs i…
- CVE-2021-37709MEDIUMCVSS 6.5EG 6.52021-08-16
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for …
- CVE-2021-37759CRITICALCVSS 9.8EG 9.82021-07-31
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
- CVE-2021-37760CRITICALCVSS 9.8EG 9.82021-07-31
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
- CVE-2021-37861MEDIUMCVSS 5.8EG 5.82021-12-09
Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
- CVE-2021-3791MEDIUMCVSS 6.5EG 6.52021-11-12
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such a…
- CVE-2021-38283HIGHCVSS 7.5EG 7.52021-11-29
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.
- CVE-2021-38939MEDIUMCVSS 5.3EG 5.32022-04-27
IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037.
- CVE-2021-39011MEDIUMCVSS 4.2EG 4.92023-01-20
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645.
- CVE-2021-39032MEDIUMCVSS 5.5EG 5.52022-01-14
IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 213962.
- CVE-2021-39246MEDIUMCVSS 6.1EG 6.12021-09-24
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be abl…
- CVE-2021-39291HIGHCVSS 8.8EG 8.82021-08-23
Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, N…
- CVE-2021-39715MEDIUMCVSS 4.4EG 4.42022-03-16
In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed…
- CVE-2021-39739LOWCVSS 3.3EG 3.32022-03-30
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-39900LOWCVSS 2.0EG 2.72021-10-04
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.
- CVE-2021-39913MEDIUMCVSS 6.7EG 6.72021-11-05
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local f…
- CVE-2021-40352MEDIUMCVSS 6.5EG 6.52021-09-01
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.
- CVE-2021-40364MEDIUMCVSS 5.5EG 5.52021-11-09
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIM…
- CVE-2021-41543MEDIUMCVSS 6.5EG 6.52022-03-08
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information…
- CVE-2021-41808LOWCVSS 2.0EG 2.32022-01-18
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
- CVE-2021-43271MEDIUMCVSS 6.8EG 6.82022-06-03
Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when configured to use local, RADIUS, or TACACS authentication) logs usernames and passwords if either is …
- CVE-2021-44234MEDIUMCVSS 5.5EG 5.52022-01-14
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
- CVE-2021-44862HIGHCVSS 8.4EG 8.42022-11-03
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not mask…
- CVE-2021-45034HIGHCVSS 7.5EG 7.52022-01-11
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODU…
- CVE-2021-45103HIGHCVSS 8.1EG 8.12022-04-06
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.
- CVE-2021-45449MEDIUMCVSS 5.5EG 5.52022-01-12
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged i…
- CVE-2022-0010HIGHCVSS 7.8EG 7.82023-05-22
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a syst…
- CVE-2022-0021LOWCVSS 3.3EG 3.32022-02-10
An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon fe…
- CVE-2022-0338MEDIUMCVSS 4.3EG 4.32022-01-25
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
- CVE-2022-0652HIGHCVSS 3.3EG 7.82022-03-22
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before…
- CVE-2022-0718MEDIUMCVSS 4.9EG 4.92022-08-29
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
- CVE-2022-0725HIGHCVSS 7.5EG 7.52022-03-10
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.
- CVE-2022-1157LOWCVSS 2.6EG 2.62022-04-11
Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged
- CVE-2022-20278MEDIUMCVSS 5.5EG 5.52022-08-12
In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not neede…
- CVE-2022-20458MEDIUMCVSS 5.5EG 5.52023-01-26
The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prin…
- CVE-2022-20630MEDIUMCVSS 4.4EG 4.42022-02-10
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected syste…
- CVE-2022-20651MEDIUMCVSS 5.5EG 5.52022-06-22
A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shar…
- CVE-2022-20768MEDIUMCVSS 4.9EG 4.92022-07-06
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerabil…
- CVE-2022-20806HIGHCVSS 4.3EG 7.12022-05-27
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive i…
- CVE-2022-20807MEDIUMCVSS 4.3EG 6.52022-05-27
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive i…
- CVE-2022-20809MEDIUMCVSS 4.3EG 6.52022-05-26
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive i…
- CVE-2022-2084MEDIUMCVSS 5.5EG 5.52023-04-19
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
- CVE-2022-22703MEDIUMCVSS 5.5EG 5.52022-01-17
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
- CVE-2022-22939MEDIUMCVSS 4.9EG 4.92022-02-04
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager …
- CVE-2022-23141HIGHCVSS 7.5EG 7.52022-07-15
ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive info…
- CVE-2022-23469LOWCVSS 3.5EG 3.52022-12-08
Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulnerability in Traefik displaying the Authorization header in its debug logs. In certain cases, if the log level is set to…
- CVE-2022-23506MEDIUMCVSS 4.3EG 4.32023-01-03
Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does not property mask sec…
- CVE-2022-23715MEDIUMCVSS 6.5EG 6.52022-08-25
A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Moni…
- CVE-2022-23716MEDIUMCVSS 5.3EG 5.32022-09-28
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →