VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 25 of 63
  • CVE-2018-1876MedNov 2, 2018
    risk 0.40cvss 6.2epss 0.00

    IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.

  • CVE-2017-5137MedFeb 5, 2017
    risk 0.40cvss 6.2epss 0.01

    An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.

  • CVE-2026-86049HigSep 17, 2026
    risk 0.39cvss 7.1epss 0.00

    Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for the request URI. A request that returns…

  • CVE-2025-66910MedDec 19, 2025
    risk 0.39cvss 6.0epss 0.00

    Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to optimize authentication performance. Upon…

  • CVE-2025-2002MedMar 12, 2025
    risk 0.39cvss 6.0epss 0.00

    CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the…

  • CVE-2025-24362HigJan 24, 2025
    risk 0.39cvss —epss 0.01

    In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables from the workflow run, including any secrets that were exposed as environment variables to the workflow. Users with read access to…

  • CVE-2023-37224MedJul 14, 2023
    risk 0.39cvss 6.0epss 0.00

    An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files.

  • CVE-2020-10750HigJun 19, 2020
    risk 0.39cvss 7.1epss 0.00

    Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. This flaw allows an attacker with access to the container's log file to discover the Kafka credentials.

  • CVE-2018-10855MedJul 3, 2018
    risk 0.39cvss 5.9epss 0.03

    Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in…

  • CVE-2018-8719MedApr 4, 2018
    risk 0.39cvss 5.3epss 0.16

    An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

  • CVE-2026-20708MedAug 11, 2026
    risk 0.38cvss —epss 0.00

    Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result…

  • CVE-2026-7824MedMay 5, 2026
    risk 0.38cvss —epss 0.00

    An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files. An attacker with administrative access to the…

  • CVE-2025-36133MedSep 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.

  • CVE-2025-24651MedApr 17, 2025
    risk 0.38cvss 5.9epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1.5.3.

  • CVE-2021-22518MedSep 12, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0

  • CVE-2024-29954MedJun 26, 2024
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail.…

  • CVE-2023-32468MedJul 26, 2023
    risk 0.38cvss 5.8epss 0.00

    Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability. A remote malicious high-privileged user could potentially exploit this vulnerability leading to exposure of this sensitive data.

  • CVE-2022-39876MedOct 7, 2022
    risk 0.38cvss 5.9epss 0.00

    Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI.

  • CVE-2022-34826MedJul 15, 2022
    risk 0.38cvss 5.9epss 0.01

    In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.

  • CVE-2021-37861MedDec 9, 2021
    risk 0.38cvss 5.8epss 0.01

    Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.