CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,256)
page 11 of 63| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0725 | Hig | 0.49 | 7.5 | 0.02 | Mar 10, 2022 | A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs. | ||
| CVE-2022-25374 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1. | ||
| CVE-2021-45034 | Hig | 0.49 | 7.5 | 0.02 | Jan 11, 2022 | A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20).… | ||
| CVE-2021-34797 | Hig | 0.49 | 7.5 | 0.03 | Jan 4, 2022 | Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or… | ||
| CVE-2021-34800 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2021 | Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147 | ||
| CVE-2021-20129 | Hig | 0.49 | 7.5 | 0.02 | Oct 13, 2021 | An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs. | ||
| CVE-2021-22024 | Hig | 0.49 | 7.5 | 0.01 | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure. | ||
| CVE-2021-28131 | Hig | 0.49 | 7.5 | 0.03 | Jul 22, 2021 | Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially constructed… | ||
| CVE-2020-21933 | Hig | 0.49 | 7.5 | 0.01 | Jul 21, 2021 | An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package. | ||
| CVE-2020-23284 | Hig | 0.49 | 7.5 | 0.01 | Jul 20, 2021 | Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database which reveals internal and sensitive information without logging into the web application. | ||
| CVE-2021-35299 | Hig | 0.49 | 7.5 | 0.01 | Jun 28, 2021 | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing. | ||
| CVE-2020-15380 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2021 | Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level. | ||
| CVE-2021-22516 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2021 | Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file. | ||
| CVE-2021-23924 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files. | ||
| CVE-2020-26605 | Hig | 0.49 | 7.5 | 0.00 | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attackers to obtain sensitive information by reading a log. The Samsung ID is SVE-2020-18596 (October 2020). | ||
| CVE-2020-25987 | Hig | 0.49 | 7.5 | 0.02 | Oct 6, 2020 | MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash. | ||
| CVE-2020-24566 | Hig | 0.49 | 7.5 | 0.02 | Sep 9, 2020 | In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password… | ||
| CVE-2020-6938 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2020 | A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files. | ||
| CVE-2020-13830 | Hig | 0.49 | 7.5 | 0.00 | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020). | ||
| CVE-2020-7654 | Hig | 0.49 | 7.5 | 0.01 | May 29, 2020 | All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG. |
- risk 0.49cvss 7.5epss 0.02
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.
- risk 0.49cvss 7.5epss 0.01
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
- risk 0.49cvss 7.5epss 0.02
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20).…
- risk 0.49cvss 7.5epss 0.03
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or…
- risk 0.49cvss 7.5epss 0.01
Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147
- risk 0.49cvss 7.5epss 0.02
An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
- risk 0.49cvss 7.5epss 0.01
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure.
- risk 0.49cvss 7.5epss 0.03
Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially constructed…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
- risk 0.49cvss 7.5epss 0.01
Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database which reveals internal and sensitive information without logging into the web application.
- risk 0.49cvss 7.5epss 0.01
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
- risk 0.49cvss 7.5epss 0.01
Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.
- risk 0.49cvss 7.5epss 0.01
Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attackers to obtain sensitive information by reading a log. The Samsung ID is SVE-2020-18596 (October 2020).
- risk 0.49cvss 7.5epss 0.02
MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.
- risk 0.49cvss 7.5epss 0.02
In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password…
- risk 0.49cvss 7.5epss 0.01
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).
- risk 0.49cvss 7.5epss 0.01
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.