CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,196)
page 27 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-51497 | Med | 0.36 | 5.5 | 0.00 | Jul 17, 2025 | An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be disabled in version… | ||
| CVE-2025-30483 | Med | 0.36 | 5.5 | 0.00 | Jul 15, 2025 | Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | ||
| CVE-2025-5463 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information. | ||
| CVE-2025-50200 | Med | 0.36 | 5.5 | 0.00 | Jun 19, 2025 | RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including… | ||
| CVE-2025-31199 | Med | 0.36 | 5.5 | 0.00 | May 29, 2025 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, visionOS 2.4. An app may be able to access sensitive user data. | ||
| CVE-2025-2300 | Med | 0.36 | 5.5 | 0.00 | Apr 22, 2025 | Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00. | ||
| CVE-2025-1998 | Med | 0.36 | 5.5 | 0.00 | Mar 27, 2025 | IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores potentially sensitive authentication token information in log files that could be read by a local user. | ||
| CVE-2025-0273 | Med | 0.36 | 5.5 | 0.00 | Mar 27, 2025 | HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user. | ||
| CVE-2025-0736 | Med | 0.36 | 5.5 | 0.00 | Jan 28, 2025 | A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and… | ||
| CVE-2024-54519 | Med | 0.36 | 5.5 | 0.00 | Jan 27, 2025 | The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive location information. | ||
| CVE-2025-24457 | Med | 0.36 | 5.5 | 0.01 | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | ||
| CVE-2024-11923 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2025 | Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3 | ||
| CVE-2025-21323 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2025-21321 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2025-21320 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2025-21319 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2025-21318 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2025-21317 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2025-21316 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2024-40679 | Med | 0.36 | 5.5 | 0.00 | Jan 8, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions. |
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be disabled in version…
- risk 0.36cvss 5.5epss 0.00
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information.
- risk 0.36cvss 5.5epss 0.00
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including…
- risk 0.36cvss 5.5epss 0.00
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, visionOS 2.4. An app may be able to access sensitive user data.
- risk 0.36cvss 5.5epss 0.00
Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00.
- risk 0.36cvss 5.5epss 0.00
IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores potentially sensitive authentication token information in log files that could be read by a local user.
- risk 0.36cvss 5.5epss 0.00
HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.
- risk 0.36cvss 5.5epss 0.00
A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and…
- risk 0.36cvss 5.5epss 0.00
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive location information.
- risk 0.36cvss 5.5epss 0.01
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
- risk 0.36cvss 5.5epss 0.00
Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.