VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 19 of 60
  • CVE-2022-44624MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters

  • CVE-2022-41553MedNov 1, 2022
    risk 0.42cvss 6.5epss 0.00

    Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive…

  • CVE-2022-3499MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of agent logs and data is present.

  • CVE-2022-23715MedAug 25, 2022
    risk 0.42cvss 6.5epss 0.01

    A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are…

  • CVE-2022-38149HigAug 17, 2022
    risk 0.42cvss 7.5epss 0.01

    HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.

  • CVE-2022-32193MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.

  • CVE-2022-28859MedMay 5, 2022
    risk 0.42cvss 6.5epss 0.01

    On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh and nethsm-thales-install.sh) expose the Net HSM partition password. Note: Software versions which have reached End of Technical…

  • CVE-2022-24757HigMar 23, 2022
    risk 0.42cvss 7.5epss 0.01

    The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other…

  • CVE-2022-25518MedMar 22, 2022
    risk 0.42cvss 6.5epss 0.01

    In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the password of the users who login to the application by querying the database table.

  • CVE-2021-41543MedMar 8, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could…

  • CVE-2021-22030MedNov 19, 2021
    risk 0.42cvss 6.5epss 0.01

    In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can read sensitive(credentials) information about users

  • CVE-2021-3791MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.00

    An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.

  • CVE-2020-24038MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.01

    myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

  • CVE-2021-32074HigMay 7, 2021
    risk 0.42cvss 7.5epss 0.02

    HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.

  • CVE-2021-3167MedMar 15, 2021
    risk 0.42cvss 6.5epss 0.01

    In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.

  • CVE-2021-20359MedFeb 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in log files that could be obtained by an unauthorized user. IBM X-Force ID: 194966.

  • CVE-2020-26199MedJan 5, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker…

  • CVE-2020-4671MedNov 16, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an authenticatedl user. IBM X-Force ID: 186284.

  • CVE-2020-11643MedOct 15, 2020
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign domains.

  • CVE-2020-5389MedOct 8, 2020
    risk 0.42cvss 6.5epss 0.01

    Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vulnerability. Authenticated low privileged OMIMSCC users may be able to retrieve sensitive information from the logs.