VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 34 of 60
  • CVE-2020-14518MedAug 21, 2020
    risk 0.35cvss 5.3epss 0.01

    Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.

  • CVE-2020-15829MedAug 8, 2020
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.

  • CVE-2019-14864MedJan 2, 2020
    risk 0.35cvss 6.5epss 0.02

    Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any…

  • CVE-2019-3429MedDec 23, 2019
    risk 0.35cvss 5.3epss 0.01

    All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information.

  • CVE-2019-3649MedNov 13, 2019
    risk 0.35cvss 5.3epss 0.01

    Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incorrectly recorded data from log files.

  • CVE-2019-11465MedSep 10, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged…

  • CVE-2019-11250MedAug 29, 2019
    risk 0.35cvss 6.5epss 0.02

    The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token…

  • CVE-2019-10370MedAug 7, 2019
    risk 0.35cvss 6.5epss 0.01

    Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.

  • CVE-2019-10358MedJul 31, 2019
    risk 0.35cvss 6.5epss 0.01

    Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.

  • CVE-2018-3776MedAug 12, 2018
    risk 0.35cvss 5.3epss 0.01

    Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

  • CVE-2018-1999036MedAug 1, 2018
    risk 0.35cvss 6.5epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.

  • CVE-2026-19363MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation results in sensitive information in log files. The attack can be executed remotely. `src/handler.rs`…

  • CVE-2026-45040MedMay 28, 2026
    risk 0.34cvss epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (JWT), SecretAccessKey, and full JWT…

  • CVE-2026-41182MedApr 23, 2026
    risk 0.34cvss 5.3epss 0.00

    LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to…

  • CVE-2025-70040MedMar 9, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allows an attacker to obtain sensitive information.

  • CVE-2025-5781MedFeb 25, 2026
    risk 0.34cvss 5.2epss 0.00

    Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi…

  • CVE-2026-2605MedFeb 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS.

  • CVE-2025-10486MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the…

  • CVE-2025-6587MedJul 3, 2025
    risk 0.34cvss epss 0.00

    System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain…

  • CVE-2025-3911MedApr 29, 2025
    risk 0.34cvss epss 0.00

    Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain sensitive…