CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,256)
page 10 of 63| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47390 | Hig | 0.49 | 7.5 | 0.01 | Nov 11, 2023 | Headscale through 0.22.3 writes bearer tokens to info-level logs. | ||
| CVE-2023-5499 | Hig | 0.49 | 7.5 | 0.01 | Oct 10, 2023 | Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages,… | ||
| CVE-2023-44155 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | ||
| CVE-2023-41308 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-35695 | Hig | 0.49 | 7.5 | 0.01 | Jun 26, 2023 | A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product. | ||
| CVE-2023-33001 | Hig | 0.49 | 7.5 | 0.01 | May 16, 2023 | Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled. | ||
| CVE-2023-22362 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2023 | SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2,… | ||
| CVE-2023-25164 | Hig | 0.49 | 8.6 | 0.01 | Feb 8, 2023 | Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be added in plaintext to the index.js… | ||
| CVE-2021-36544 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL. | ||
| CVE-2022-2721 | Hig | 0.49 | 7.5 | 0.01 | Nov 25, 2022 | In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled. | ||
| CVE-2022-39821 | Hig | 0.49 | 7.5 | 0.01 | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem. | ||
| CVE-2022-39046 | Hig | 0.49 | 7.5 | 0.02 | Aug 31, 2022 | An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the… | ||
| CVE-2022-34570 | Hig | 0.49 | 7.5 | 0.01 | Jul 25, 2022 | WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page. | ||
| CVE-2022-32556 | Hig | 0.49 | 7.5 | 0.01 | Jul 21, 2022 | An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes. | ||
| CVE-2022-23141 | Hig | 0.49 | 7.5 | 0.01 | Jul 15, 2022 | ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information. | ||
| CVE-2022-33737 | Hig | 0.49 | 7.5 | 0.01 | Jul 6, 2022 | The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password | ||
| CVE-2022-32565 | Hig | 0.49 | 7.5 | 0.01 | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids. | ||
| CVE-2022-27442 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2022 | TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password. | ||
| CVE-2022-24758 | Hig | 0.49 | 7.5 | 0.01 | Mar 31, 2022 | The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter… | ||
| CVE-2022-27192 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files. |
- risk 0.49cvss 7.5epss 0.01
Headscale through 0.22.3 writes bearer tokens to info-level logs.
- risk 0.49cvss 7.5epss 0.01
Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages,…
- risk 0.49cvss 7.5epss 0.01
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- risk 0.49cvss 7.5epss 0.01
Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.01
A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product.
- risk 0.49cvss 7.5epss 0.01
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
- risk 0.49cvss 7.5epss 0.01
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2,…
- risk 0.49cvss 8.6epss 0.01
Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be added in plaintext to the index.js…
- risk 0.49cvss 7.5epss 0.01
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.
- risk 0.49cvss 7.5epss 0.01
In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled.
- risk 0.49cvss 7.5epss 0.01
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the…
- risk 0.49cvss 7.5epss 0.01
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
- risk 0.49cvss 7.5epss 0.01
ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.
- risk 0.49cvss 7.5epss 0.01
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.
- risk 0.49cvss 7.5epss 0.01
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
- risk 0.49cvss 7.5epss 0.01
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter…
- risk 0.49cvss 7.5epss 0.01
The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.