VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 18 of 60
  • CVE-2021-22533MedSep 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

  • CVE-2024-42056MedAug 22, 2024
    risk 0.42cvss 6.5epss 0.00

    Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.

  • CVE-2024-41978MedAug 13, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family…

  • CVE-2024-6977MedJul 31, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue…

  • CVE-2024-41178HigJul 23, 2024
    risk 0.42cvss 7.5epss 0.01

    Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens.  On certain error conditions, the logs may contain the OIDC token passed to AssumeRoleWithWebIdentity…

  • CVE-2024-41824MedJul 22, 2024
    risk 0.42cvss 6.4epss 0.00

    In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

  • CVE-2024-36127HigJun 3, 2024
    risk 0.42cvss 7.5epss 0.00

    apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.

  • CVE-2024-32051MedApr 24, 2024
    risk 0.42cvss 6.5epss 0.00

    Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may obtain sensitive information.

  • CVE-2024-31391MedApr 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentication and create…

  • CVE-2024-22352MedMar 21, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361.

  • CVE-2023-46215HigOct 28, 2023
    risk 0.42cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend Note: the vulnerability is about the information…

  • CVE-2023-44483MedOct 20, 2023
    risk 0.42cvss 6.5epss 0.01

    All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users…

  • CVE-2023-3335MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users  to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00.

  • CVE-2020-24804MedAug 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information via audit logs.

  • CVE-2023-20891MedJul 26, 2023
    risk 0.42cvss 6.5epss 0.01

    The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can…

  • CVE-2023-26023MedJul 19, 2023
    risk 0.42cvss 6.5epss 0.01

    Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.

  • CVE-2023-20885MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to…

  • CVE-2023-25721MedMar 28, 2023
    risk 0.42cvss 6.5epss 0.01

    Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to…

  • CVE-2022-43870MedFeb 22, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.

  • CVE-2022-48319MedFeb 20, 2023
    risk 0.42cvss 6.5epss 0.00

    Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.