VYPR

CWE-117

Improper Output Neutralization for Logs

BaseDraftLikelihood: Medium

Description

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-268 · CAPEC-81 · CAPEC-93

CVEs mapped to this weakness (111)

page 6 of 6
  • CVE-2025-54813HigAug 22, 2025
    risk 0.00cvss 7.5epss 0.01

    Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as…

  • CVE-2025-54812MedAug 22, 2025
    risk 0.00cvss 5.4epss 0.01

    Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. If untrusted data is used to retrieve the name of a logger, an attacker could theoretically inject HTML or…

  • CVE-2025-54389MedAug 14, 2025
    risk 0.00cvss 6.2epss 0.00

    AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. An attacker can craft a malicious filename by including terminal escape sequences to hide the addition or removal of the file from the…

  • CVE-2024-12580MedMar 20, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or filtered, leading to potential…

  • CVE-2024-8334MedAug 30, 2024
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as problematic. This issue affects the function LogHandler of the file middleware/log.go. The manipulation leads to improper output neutralization for logs. The…

  • CVE-2024-8297MedAug 29, 2024
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the argument Authorization leads to improper…

  • CVE-2023-46322CriOct 23, 2023
    risk 0.00cvss 9.8epss 0.01

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.

  • CVE-2023-46321CriOct 23, 2023
    risk 0.00cvss 9.8epss 0.01

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.

  • CVE-2023-37275LowJul 13, 2023
    risk 0.00cvss 3.1epss 0.00

    Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GPT command line UI makes heavy use of color-coded print statements to signify different types of system messages to the user, including messages that are…

  • CVE-2020-25646HigOct 29, 2020
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality

  • CVE-2018-10932MedAug 21, 2018
    risk 0.00cvss 4.3epss 0.01

    lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.