VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 15 of 63
  • CVE-2026-20144MedFeb 18, 2026
    risk 0.44cvss 6.8epss 0.00

    In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the the Splunk…

  • CVE-2026-20142MedFeb 18, 2026
    risk 0.44cvss 6.8epss 0.00

    In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the RSA `accessKey` value from the [Authentication.conf…

  • CVE-2026-20138MedFeb 18, 2026
    risk 0.44cvss 6.8epss 0.00

    In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the `integrationKey`, `secretKey`, and `appSecretKey` secrets, generated…

  • CVE-2025-66411HigDec 3, 2025
    risk 0.44cvss 7.8epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace…

  • CVE-2025-8864MedAug 11, 2025
    risk 0.44cvss —epss 0.00

    Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs

  • CVE-2025-7371MedJul 22, 2025
    risk 0.44cvss 6.8epss 0.00

    Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during…

  • CVE-2025-25002MedApr 8, 2025
    risk 0.44cvss 6.8epss 0.01

    Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.

  • CVE-2022-43936MedNov 21, 2024
    risk 0.44cvss 6.8epss 0.01

    Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.

  • CVE-2024-32757MedJul 2, 2024
    risk 0.44cvss 6.8epss 0.00

    Under certain circumstances unnecessary user details are provided within system logs

  • CVE-2024-27157MedJun 14, 2024
    risk 0.44cvss 6.8epss 0.00

    The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. As for the affected products/models/versions, see the reference URL.

  • CVE-2024-27156MedJun 14, 2024
    risk 0.44cvss 6.8epss 0.00

    The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. As for the affected products/models/versions, see the reference…

  • CVE-2024-22440MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.00

    A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability could cause disclosure of sensitive information in log files.

  • CVE-2023-46231MedJan 30, 2024
    risk 0.44cvss 6.8epss 0.00

    In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.

  • CVE-2023-49923MedDec 12, 2023
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or private information in the App Search logs.…

  • CVE-2022-27599MedSep 8, 2023
    risk 0.44cvss 6.7epss 0.00

    An insertion of sensitive information into Log file vulnerability has been reported to affect product. If exploited, the vulnerability possibly provides local authenticated administrators with an additional, less-protected path to acquiring the information via unspecified…

  • CVE-2023-31426MedAug 1, 2023
    risk 0.44cvss 6.8epss 0.01

    The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to access sensitive information.

  • CVE-2023-2514MedMay 12, 2023
    risk 0.44cvss 6.7epss 0.01

    Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. 

  • CVE-2022-42439MedFeb 6, 2023
    risk 0.44cvss 6.8epss 0.01

    IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attacker. IBM X-Force ID: 238211.

  • CVE-2022-3018MedOct 28, 2022
    risk 0.44cvss 6.8epss 0.01

    An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from…

  • CVE-2022-31239MedOct 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.