VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 21 of 60
  • CVE-2013-1771HigNov 7, 2019
    risk 0.42cvss 7.5epss 0.03

    The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.

  • CVE-2019-11549MedSep 9, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

  • CVE-2019-15508MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…

  • CVE-2019-15507MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…

  • CVE-2019-5634MedAug 22, 2019
    risk 0.42cvss 6.5epss 0.00

    An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile…

  • CVE-2019-13515MedAug 15, 2019
    risk 0.42cvss 6.5epss 0.01

    OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.

  • CVE-2019-1953MedAug 8, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced to modify the…

  • CVE-2016-10819MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).

  • CVE-2019-14268MedJul 25, 2019
    risk 0.42cvss 6.5epss 0.01

    In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.3.…

  • CVE-2019-13098MedJul 22, 2019
    risk 0.42cvss 6.5epss 0.01

    The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior…

  • CVE-2018-19583MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.02

    GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

  • CVE-2019-6157MedApr 22, 2019
    risk 0.42cvss 6.5epss 0.01

    In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.

  • CVE-2019-8944MedFeb 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.

  • CVE-2018-19014MedJan 28, 2019
    risk 0.42cvss 6.5epss 0.01

    Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about…

  • CVE-2018-0504MedOct 4, 2018
    risk 0.42cvss 6.5epss 0.03

    Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid

  • CVE-2018-7682MedJun 22, 2018
    risk 0.42cvss 6.5epss 0.01

    Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.

  • CVE-2018-3817MedMar 30, 2018
    risk 0.42cvss 6.5epss 0.01

    When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.

  • CVE-2018-7204HigMar 7, 2018
    risk 0.42cvss 7.5epss 0.03

    inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not…

  • CVE-2018-2372MedFeb 14, 2018
    risk 0.42cvss 6.5epss 0.01

    A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.

  • CVE-2017-11134MedAug 1, 2017
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them.