CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,196)
page 21 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-1771 | Hig | 0.42 | 7.5 | 0.03 | Nov 7, 2019 | The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo. | ||
| CVE-2019-11549 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors. | ||
| CVE-2019-15508 | Med | 0.42 | 6.5 | 0.01 | Aug 23, 2019 | In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is… | ||
| CVE-2019-15507 | Med | 0.42 | 6.5 | 0.01 | Aug 23, 2019 | In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is… | ||
| CVE-2019-5634 | Med | 0.42 | 6.5 | 0.00 | Aug 22, 2019 | An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile… | ||
| CVE-2019-13515 | Med | 0.42 | 6.5 | 0.01 | Aug 15, 2019 | OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information. | ||
| CVE-2019-1953 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2019 | A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced to modify the… | ||
| CVE-2016-10819 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125). | ||
| CVE-2019-14268 | Med | 0.42 | 6.5 | 0.01 | Jul 25, 2019 | In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.3.… | ||
| CVE-2019-13098 | Med | 0.42 | 6.5 | 0.01 | Jul 22, 2019 | The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior… | ||
| CVE-2018-19583 | Med | 0.42 | 6.5 | 0.02 | Jul 10, 2019 | GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token. | ||
| CVE-2019-6157 | Med | 0.42 | 6.5 | 0.01 | Apr 22, 2019 | In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support. | ||
| CVE-2019-8944 | Med | 0.42 | 6.5 | 0.02 | Feb 20, 2019 | An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files. | ||
| CVE-2018-19014 | Med | 0.42 | 6.5 | 0.01 | Jan 28, 2019 | Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about… | ||
| CVE-2018-0504 | Med | 0.42 | 6.5 | 0.03 | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid | ||
| CVE-2018-7682 | Med | 0.42 | 6.5 | 0.01 | Jun 22, 2018 | Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains. | ||
| CVE-2018-3817 | Med | 0.42 | 6.5 | 0.01 | Mar 30, 2018 | When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information. | ||
| CVE-2018-7204 | Hig | 0.42 | 7.5 | 0.03 | Mar 7, 2018 | inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not… | ||
| CVE-2018-2372 | Med | 0.42 | 6.5 | 0.01 | Feb 14, 2018 | A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication. | ||
| CVE-2017-11134 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them. |
- risk 0.42cvss 7.5epss 0.03
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.
- risk 0.42cvss 6.5epss 0.01
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…
- risk 0.42cvss 6.5epss 0.01
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…
- risk 0.42cvss 6.5epss 0.00
An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile…
- risk 0.42cvss 6.5epss 0.01
OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced to modify the…
- risk 0.42cvss 6.5epss 0.01
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
- risk 0.42cvss 6.5epss 0.01
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.3.…
- risk 0.42cvss 6.5epss 0.01
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior…
- risk 0.42cvss 6.5epss 0.02
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.
- risk 0.42cvss 6.5epss 0.01
In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.
- risk 0.42cvss 6.5epss 0.02
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
- risk 0.42cvss 6.5epss 0.01
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about…
- risk 0.42cvss 6.5epss 0.03
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
- risk 0.42cvss 6.5epss 0.01
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
- risk 0.42cvss 6.5epss 0.01
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
- risk 0.42cvss 7.5epss 0.03
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not…
- risk 0.42cvss 6.5epss 0.01
A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them.