VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 10 of 63
  • CVE-2023-47390HigNov 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Headscale through 0.22.3 writes bearer tokens to info-level logs.

  • CVE-2023-5499HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages,…

  • CVE-2023-44155HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-41308HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-35695HigJun 26, 2023
    risk 0.49cvss 7.5epss 0.01

    A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product.

  • CVE-2023-33001HigMay 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

  • CVE-2023-22362HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.01

    SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2,…

  • CVE-2023-25164HigFeb 8, 2023
    risk 0.49cvss 8.6epss 0.01

    Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be added in plaintext to the index.js…

  • CVE-2021-36544HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.

  • CVE-2022-2721HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled.

  • CVE-2022-39821HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.

  • CVE-2022-39046HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the…

  • CVE-2022-34570HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.

  • CVE-2022-32556HigJul 21, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.

  • CVE-2022-23141HigJul 15, 2022
    risk 0.49cvss 7.5epss 0.01

    ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.

  • CVE-2022-33737HigJul 6, 2022
    risk 0.49cvss 7.5epss 0.01

    The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password

  • CVE-2022-32565HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.

  • CVE-2022-27442HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.

  • CVE-2022-24758HigMar 31, 2022
    risk 0.49cvss 7.5epss 0.01

    The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter…

  • CVE-2022-27192HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.