VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 29 of 60
  • CVE-2023-45241MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 37391.

  • CVE-2023-4688MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433.

  • CVE-2023-32455MedJul 20, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

  • CVE-2023-32447MedJul 20, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

  • CVE-2023-32446MedJul 20, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

  • CVE-2023-32392MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to read sensitive location information.

  • CVE-2023-30610MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When…

  • CVE-2022-48228MedApr 4, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify and Sentinel Installer log files, aka CORE-7362.

  • CVE-2023-1550MedMar 29, 2023
    risk 0.36cvss 5.5epss 0.00

    Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is…

  • CVE-2023-20859MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.

  • CVE-2022-3902MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the…

  • CVE-2022-20458MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prints out the…

  • CVE-2022-33187MedDec 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.

  • CVE-2022-44745MedNov 7, 2022
    risk 0.36cvss 5.5epss 0.00

    Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.

  • CVE-2022-28625MedAug 31, 2022
    risk 0.36cvss 5.5epss 0.00

    A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality,…

  • CVE-2022-29550MedAug 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (from environment variables) to disk in cleartext. NOTE: there are no common…

  • CVE-2022-20278MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20651MedJun 22, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this…

  • CVE-2022-30148MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Windows Desired State Configuration (DSC) Information Disclosure Vulnerability

  • CVE-2022-28161MedMay 9, 2022
    risk 0.36cvss 5.5epss 0.00

    An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authenticated, local attacker to view sensitive information such as ssh passwords in filetansfer.log in debug mode. To exploit this vulnerability, the…