VYPR

CWE-117

Improper Output Neutralization for Logs

BaseDraftLikelihood: Medium

Description

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-268 · CAPEC-81 · CAPEC-93

CVEs mapped to this weakness (128)

page 5 of 7
  • CVE-2025-0754MedJan 28, 2025
    risk 0.28cvss 4.3epss 0.00

    The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh…

  • CVE-2023-6484MedApr 25, 2024
    risk 0.28cvss 5.3epss 0.01

    A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.

  • CVE-2023-38020MedFeb 2, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.

  • CVE-2021-23266MedMay 16, 2022
    risk 0.28cvss 4.3epss 0.01

    An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.

  • CVE-2021-22096MedOct 28, 2021
    risk 0.28cvss 4.3epss 0.01

    In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

  • CVE-2017-8761MedJun 2, 2021
    risk 0.28cvss 4.3epss 0.01

    In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

  • CVE-2020-4072MedJun 25, 2020
    risk 0.28cvss 5.3epss 0.01

    In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.…

  • CVE-2026-15603MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An…

  • CVE-2026-44256MedAug 19, 2026
    risk 0.27cvss 5.3epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic authentication username before credential validation and passes it to the access logger without…

  • CVE-2025-11065MedJan 26, 2026
    risk 0.27cvss 5.3epss 0.00

    A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data…

  • CVE-2025-25294MedMar 6, 2025
    risk 0.27cvss 5.3epss 0.00

    Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to 1.2.7 and 1.3.1 a default Envoy Proxy access log configuration is used. This format is vulnerable to log injection…

  • CVE-2024-1681MedApr 19, 2024
    risk 0.27cvss 5.3epss 0.01

    corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. This vulnerability allows attackers to…

  • CVE-2025-14684MedMar 25, 2026
    risk 0.26cvss 4.0epss 0.00

    IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

  • CVE-2025-12755MedFeb 17, 2026
    risk 0.26cvss 4.0epss 0.00

    IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2, CD, and LTS 9.3.x–9.4.x releases) contain a vulnerability where log messages are not properly neutralized before being written to log files. This…

  • CVE-2025-11537MedFeb 10, 2026
    risk 0.26cvss 5.0epss 0.00

    A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log…

  • CVE-2025-48432MedJun 5, 2025
    risk 0.26cvss 4.0epss 0.01

    An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or…

  • CVE-2024-0690MedFeb 6, 2024
    risk 0.26cvss 5.0epss 0.00

    An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive…

  • CVE-2023-1711MedMay 30, 2023
    risk 0.26cvss 4.0epss 0.00

    A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information. List of CPEs: * cpe:2.3:a:hitachienergy:foxman_un:R9C:*:*:*:*:*…

  • CVE-2020-14330MedSep 11, 2020
    risk 0.26cvss 5.0epss 0.01

    An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other…

  • CVE-2026-11538LowSep 18, 2026
    risk 0.24cvss 3.7epss 0.00

    IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.