VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 17 of 63
  • CVE-2026-66780MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters'…

  • CVE-2026-18710MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and…

  • CVE-2026-65945MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

  • CVE-2026-11820MedJun 23, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via GET requests. This causes credentials…

  • CVE-2026-44052HigMay 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.

  • CVE-2026-44516HigMay 14, 2026
    risk 0.42cvss 7.6epss 0.00

    Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls made via Spring's RestClient and logs the full request body, response body, and…

  • CVE-2026-41219MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2026-31987HigApr 16, 2026
    risk 0.42cvss 7.5epss 0.01

    JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.

  • CVE-2025-66236HigApr 13, 2026
    risk 0.42cvss 7.5epss 0.00

    Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not clear or explicit…

  • CVE-2026-34487HigApr 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13…

  • CVE-2026-4901MedApr 9, 2026
    risk 0.42cvss 6.5epss 0.00

    AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an…

  • CVE-2026-32982HigMar 31, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError…

  • CVE-2026-24308HigMar 7, 2026
    risk 0.42cvss 7.5epss 0.01

    Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering…

  • CVE-2026-2350MedFeb 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.

  • CVE-2026-1292MedFeb 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.

  • CVE-2026-1495MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server.

  • CVE-2026-25846MedFeb 9, 2026
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

  • CVE-2026-22782HigJan 16, 2026
    risk 0.42cvss 7.5epss 0.01

    RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables forged RPC calls. In…

  • CVE-2025-68675HigJan 16, 2026
    risk 0.42cvss 7.5epss 0.02

    In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log…

  • CVE-2025-14437HigDec 18, 2025
    risk 0.42cvss 7.5epss 0.02

    The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API…