VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 33 of 60
  • CVE-2025-59355MedJan 19, 2026
    risk 0.35cvss 6.5epss 0.00

    A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive information such as Hive…

  • CVE-2025-9985MedSep 26, 2025
    risk 0.35cvss 5.3epss 0.11

    The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information…

  • CVE-2025-48493MedJun 5, 2025
    risk 0.35cvss 6.5epss 0.00

    The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and password. That might be…

  • CVE-2025-30677MedApr 9, 2025
    risk 0.35cvss 6.5epss 0.01

    Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in application logs. This vulnerability can…

  • CVE-2025-1296MedMar 10, 2025
    risk 0.35cvss 6.5epss 0.00

    Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise…

  • CVE-2025-1979MedMar 6, 2025
    risk 0.35cvss 6.4epss 0.00

    Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If the redis password is passed as an argument, it will be logged and could potentially leak the…

  • CVE-2024-11193MedNov 13, 2024
    risk 0.35cvss 6.5epss 0.00

    An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application logs. This flaw results in the unintentional exposure of sensitive information in Yugabyte Anywhere logs, potentially allowing unauthorized…

  • CVE-2024-37283MedAug 12, 2024
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By default the log level is set to info, where no leak occurs.

  • CVE-2024-3744MedMay 15, 2024
    risk 0.35cvss 6.5epss 0.00

    A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. Tokens…

  • CVE-2024-1102MedApr 25, 2024
    risk 0.35cvss 6.5epss 0.01

    A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.

  • CVE-2024-28154MedMar 6, 2024
    risk 0.35cvss 6.5epss 0.01

    Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

  • CVE-2023-51702MedJan 24, 2024
    risk 0.35cvss 6.5epss 0.00

    Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption.…

  • CVE-2023-2878MedJun 7, 2023
    risk 0.35cvss 6.5epss 0.00

    Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.

  • CVE-2023-24827MedFeb 7, 2023
    risk 0.35cvss 6.5epss 0.01

    syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure flaw was found in Syft versions v0.69.0 and v0.69.1. This flaw leaks the password stored in the SYFT_ATTEST_PASSWORD environment…

  • CVE-2022-33911MedJul 12, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.

  • CVE-2021-38939MedApr 27, 2022
    risk 0.35cvss 5.3epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037.

  • CVE-2021-25009MedMar 7, 2022
    risk 0.35cvss 5.3epss 0.01

    The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses

  • CVE-2021-37709MedAug 16, 2021
    risk 0.35cvss 6.5epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3,…

  • CVE-2017-17675MedMay 19, 2021
    risk 0.35cvss 5.3epss 0.01

    BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.

  • CVE-2020-25640MedNov 24, 2020
    risk 0.35cvss 5.3epss 0.01

    A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.