CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,256)
page 33 of 63| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1623 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to 19.2R1. | ||
| CVE-2020-1622 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1. | ||
| CVE-2020-1621 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | ||
| CVE-2020-1620 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | ||
| CVE-2020-4083 | Med | 0.36 | 5.5 | 0.00 | Mar 5, 2020 | HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user. | ||
| CVE-2020-7215 | Med | 0.36 | 5.5 | 0.00 | Jan 20, 2020 | An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any… | ||
| CVE-2014-3536 | Med | 0.36 | 5.5 | 0.00 | Dec 15, 2019 | CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration | ||
| CVE-2019-19039 | Med | 0.36 | 5.5 | 0.01 | Nov 21, 2019 | __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team… | ||
| CVE-2019-16210 | Med | 0.36 | 5.5 | 0.00 | Nov 8, 2019 | Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save. | ||
| CVE-2019-16206 | Med | 0.36 | 5.5 | 0.00 | Nov 8, 2019 | The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information. | ||
| CVE-2018-20956 | Med | 0.36 | 5.5 | 0.00 | Aug 8, 2019 | Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31. | ||
| CVE-2019-10194 | Med | 0.36 | 5.5 | 0.00 | Jul 11, 2019 | Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts. | ||
| CVE-2019-4299 | Med | 0.36 | 5.5 | 0.00 | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765. | ||
| CVE-2019-4143 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2019 | The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log. IBM X-Force ID: 158348. | ||
| CVE-2018-16889 | Med | 0.36 | 5.5 | 0.01 | Jan 28, 2019 | Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable. | ||
| CVE-2019-0004 | Med | 0.36 | 5.5 | 0.00 | Jan 15, 2019 | On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3. | ||
| CVE-2018-15001 | Med | 0.36 | 5.5 | 0.00 | Dec 28, 2018 | The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named… | ||
| CVE-2018-19863 | Med | 0.36 | 5.5 | 0.00 | Dec 22, 2018 | An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data passed from Safari to 1Password could be logged locally on the user's machine. This data could include usernames and passwords that… | ||
| CVE-2018-1768 | Med | 0.36 | 5.6 | 0.00 | Sep 26, 2018 | IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log file. IBM X-Force ID: 148622. | ||
| CVE-2018-6599 | Med | 0.36 | 5.5 | 0.00 | Aug 29, 2018 | An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Android log on the SD card. The system-wide Android logs are not… |
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to 19.2R1.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- risk 0.36cvss 5.5epss 0.00
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any…
- risk 0.36cvss 5.5epss 0.00
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
- risk 0.36cvss 5.5epss 0.01
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team…
- risk 0.36cvss 5.5epss 0.00
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
- risk 0.36cvss 5.5epss 0.00
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.
- risk 0.36cvss 5.5epss 0.00
Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31.
- risk 0.36cvss 5.5epss 0.00
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.
- risk 0.36cvss 5.5epss 0.00
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765.
- risk 0.36cvss 5.5epss 0.00
The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log. IBM X-Force ID: 158348.
- risk 0.36cvss 5.5epss 0.01
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
- risk 0.36cvss 5.5epss 0.00
On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
- risk 0.36cvss 5.5epss 0.00
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data passed from Safari to 1Password could be logged locally on the user's machine. This data could include usernames and passwords that…
- risk 0.36cvss 5.6epss 0.00
IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log file. IBM X-Force ID: 148622.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Android log on the SD card. The system-wide Android logs are not…