CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,196)
page 25 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20289 | Med | 0.37 | 5.7 | 0.00 | Aug 5, 2026 | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by… | ||
| CVE-2025-62879 | Med | 0.37 | 6.8 | 0.00 | Mar 4, 2026 | A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs. | ||
| CVE-2022-43937 | Med | 0.37 | 5.7 | 0.00 | Nov 21, 2024 | Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a | ||
| CVE-2024-28072 | Med | 0.37 | 5.7 | 0.01 | May 3, 2024 | A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. | ||
| CVE-2023-6687 | Med | 0.37 | 6.8 | 0.01 | Dec 12, 2023 | An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Elastic Agent… | ||
| CVE-2023-49922 | Med | 0.37 | 6.8 | 0.01 | Dec 12, 2023 | An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Beats or… | ||
| CVE-2023-0815 | Med | 0.37 | 6.8 | 0.01 | Feb 23, 2023 | Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4.… | ||
| CVE-2020-5414 | Med | 0.37 | 5.7 | 0.01 | Jul 31, 2020 | VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the… | ||
| CVE-2026-19502 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2026 | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext… | ||
| CVE-2026-18097 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. | ||
| CVE-2026-11819 | Med | 0.36 | 5.5 | 0.00 | Jun 23, 2026 | Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into… | ||
| CVE-2025-46313 | Med | 0.36 | 5.5 | 0.00 | Jun 11, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. | ||
| CVE-2026-9751 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text. | ||
| CVE-2026-9735 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction. | ||
| CVE-2026-5515 | Med | 0.36 | 5.5 | 0.00 | May 27, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. | ||
| CVE-2025-13755 | Med | 0.36 | 5.5 | 0.00 | May 26, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user. | ||
| CVE-2026-44479 | Med | 0.36 | 5.5 | 0.00 | May 13, 2026 | Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), commands that cannot complete autonomously emit JSON payloads with suggested… | ||
| CVE-2026-32218 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32217 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32215 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. |
- risk 0.37cvss 5.7epss 0.00
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by…
- risk 0.37cvss 6.8epss 0.00
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
- risk 0.37cvss 5.7epss 0.00
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a
- risk 0.37cvss 5.7epss 0.01
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
- risk 0.37cvss 6.8epss 0.01
An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Elastic Agent…
- risk 0.37cvss 6.8epss 0.01
An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Beats or…
- risk 0.37cvss 6.8epss 0.01
Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4.…
- risk 0.37cvss 5.7epss 0.01
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the…
- risk 0.36cvss 5.5epss 0.00
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext…
- risk 0.36cvss 5.5epss 0.00
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
- risk 0.36cvss 5.5epss 0.00
Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into…
- risk 0.36cvss 5.5epss 0.00
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
- risk 0.36cvss 5.5epss 0.00
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
- risk 0.36cvss 5.5epss 0.00
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.
- risk 0.36cvss 5.5epss 0.00
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.
- risk 0.36cvss 5.5epss 0.00
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.
- risk 0.36cvss 5.5epss 0.00
Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), commands that cannot complete autonomously emit JSON payloads with suggested…
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.