VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 29 of 63
  • CVE-2025-50200MedJun 19, 2025
    risk 0.36cvss 5.5epss 0.00

    RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including…

  • CVE-2025-31199MedMay 29, 2025
    risk 0.36cvss 5.5epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, visionOS 2.4. An app may be able to access sensitive user data.

  • CVE-2025-2300MedApr 22, 2025
    risk 0.36cvss 5.5epss 0.00

    Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00.

  • CVE-2025-1998MedMar 27, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores potentially sensitive authentication token information in log files that could be read by a local user.

  • CVE-2025-0273MedMar 27, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.

  • CVE-2025-0736MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and…

  • CVE-2024-54519MedJan 27, 2025
    risk 0.36cvss 5.5epss 0.00

    The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive location information.

  • CVE-2025-24457MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.01

    In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs

  • CVE-2024-11923MedJan 18, 2025
    risk 0.36cvss 5.5epss 0.00

    Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3

  • CVE-2025-21323MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Memory Information Disclosure Vulnerability

  • CVE-2025-21321MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Memory Information Disclosure Vulnerability

  • CVE-2025-21320MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Memory Information Disclosure Vulnerability

  • CVE-2025-21319MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Memory Information Disclosure Vulnerability

  • CVE-2025-21318MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Memory Information Disclosure Vulnerability

  • CVE-2025-21317MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Memory Information Disclosure Vulnerability

  • CVE-2025-21316MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Memory Information Disclosure Vulnerability

  • CVE-2024-40679MedJan 8, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.

  • CVE-2024-54484MedDec 12, 2024
    risk 0.36cvss 5.5epss 0.00

    The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.

  • CVE-2024-47094MedNov 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.

  • CVE-2024-44239MedOct 28, 2024
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS…