CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,256)
page 24 of 63| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-6720 | Hig | 0.40 | — | 0.00 | May 28, 2026 | When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig… | ||
| CVE-2019-25683 | Med | 0.40 | 6.2 | 0.00 | Apr 5, 2026 | FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters… | ||
| CVE-2026-20818 | Med | 0.40 | 6.2 | 0.01 | Jan 13, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-59258 | Med | 0.40 | 6.2 | 0.01 | Oct 14, 2025 | Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-6624 | Hig | 0.40 | 7.2 | 0.00 | Jun 26, 2025 | Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI… | ||
| CVE-2025-36050 | Med | 0.40 | 6.2 | 0.00 | Jun 19, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user. | ||
| CVE-2024-45091 | Med | 0.40 | 6.2 | 0.00 | Jan 21, 2025 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs. | ||
| CVE-2024-42196 | Med | 0.40 | 6.2 | 0.00 | Dec 6, 2024 | HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs. | ||
| CVE-2024-27154 | — | Med | 0.40 | 6.2 | 0.00 | Jun 14, 2024 | Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL. | |
| CVE-2023-40694 | Med | 0.40 | 6.2 | 0.00 | May 7, 2024 | IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838. | ||
| CVE-2024-25030 | Med | 0.40 | 6.2 | 0.00 | Apr 3, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677. | ||
| CVE-2024-22464 | Med | 0.40 | 6.2 | 0.01 | Feb 8, 2024 | Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure… | ||
| CVE-2023-25682 | Med | 0.40 | 6.2 | 0.00 | Nov 22, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034. | ||
| CVE-2022-43923 | Med | 0.40 | 6.2 | 0.00 | Feb 24, 2023 | IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584. | ||
| CVE-2022-43930 | Med | 0.40 | 6.2 | 0.00 | Feb 17, 2023 | IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677. | ||
| CVE-2022-45098 | Med | 0.40 | 6.1 | 0.00 | Feb 1, 2023 | Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure. | ||
| CVE-2021-22929 | Med | 0.40 | 6.1 | 0.00 | Aug 31, 2021 | An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log. | ||
| CVE-2021-20536 | Med | 0.40 | 6.2 | 0.00 | Apr 26, 2021 | IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836. | ||
| CVE-2021-22184 | Med | 0.40 | 6.2 | 0.00 | Mar 26, 2021 | An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted. | ||
| CVE-2020-6224 | Med | 0.40 | 6.2 | 0.01 | Apr 14, 2020 | SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to… |
- risk 0.40cvss —epss 0.00
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig…
- risk 0.40cvss 6.2epss 0.00
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters…
- risk 0.40cvss 6.2epss 0.01
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.
- risk 0.40cvss 6.2epss 0.01
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
- risk 0.40cvss 7.2epss 0.00
Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI…
- risk 0.40cvss 6.2epss 0.00
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.
- risk 0.40cvss 6.2epss 0.00
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
- risk 0.40cvss 6.2epss 0.00
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
- risk 0.40cvss 6.2epss 0.00
Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.
- risk 0.40cvss 6.2epss 0.00
IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838.
- risk 0.40cvss 6.2epss 0.00
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.
- risk 0.40cvss 6.2epss 0.01
Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure…
- risk 0.40cvss 6.2epss 0.00
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.
- risk 0.40cvss 6.2epss 0.00
IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.
- risk 0.40cvss 6.2epss 0.00
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677.
- risk 0.40cvss 6.1epss 0.00
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.
- risk 0.40cvss 6.1epss 0.00
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
- risk 0.40cvss 6.2epss 0.00
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
- risk 0.40cvss 6.2epss 0.00
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.
- risk 0.40cvss 6.2epss 0.01
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to…