VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 22 of 60
  • CVE-2017-3744MedJun 20, 2017
    risk 0.42cvss 6.5epss 0.01

    In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear…

  • CVE-2016-10362MedJun 16, 2017
    risk 0.42cvss 6.5epss 0.01

    Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

  • CVE-2016-6799HigMay 9, 2017
    risk 0.42cvss 7.5epss 0.03

    Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximum of four 16 KB…

  • CVE-2026-71845MedAug 11, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in…

  • CVE-2026-71474MedAug 11, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This…

  • CVE-2026-20165MedMar 11, 2026
    risk 0.41cvss 6.3epss 0.00

    In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, and 9.3.2411.124, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve sensitive…

  • CVE-2025-54319MedJul 20, 2025
    risk 0.41cvss 6.3epss 0.00

    An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information via system logging information (syslog verbose logging that includes credentials).

  • CVE-2025-24389MedJan 27, 2025
    risk 0.41cvss 6.3epss 0.00

    Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS))…

  • CVE-2024-20491MedOct 2, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in…

  • CVE-2024-20490MedOct 2, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy…

  • CVE-2024-39532MedJul 11, 2024
    risk 0.41cvss 6.3epss 0.00

    An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. When another user performs a specific operation, sensitive…

  • CVE-2023-4380MedOct 4, 2023
    risk 0.41cvss 6.3epss 0.01

    A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and…

  • CVE-2023-32491MedAug 16, 2023
    risk 0.41cvss 6.3epss 0.00

    Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2023-21492MedKEVMay 4, 2023
    risk 0.41cvss 4.4epss 0.03

    Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

  • CVE-2018-1000089HigMar 13, 2018
    risk 0.41cvss 7.4epss 0.01

    Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you…

  • CVE-2026-9073MedJun 23, 2026
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credentials, at an informational level. The…

  • CVE-2026-6720HigMay 28, 2026
    risk 0.40cvss epss 0.00

    When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig…

  • CVE-2019-25683MedApr 5, 2026
    risk 0.40cvss 6.2epss 0.00

    FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters…

  • CVE-2026-20818MedJan 13, 2026
    risk 0.40cvss 6.2epss 0.01

    Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-59258MedOct 14, 2025
    risk 0.40cvss 6.2epss 0.01

    Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.