VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 39 of 60
  • CVE-2024-23791MedJan 29, 2024
    risk 0.32cvss 4.9epss 0.01

    Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

  • CVE-2023-3993MedAug 2, 2023
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

  • CVE-2023-20207MedJul 12, 2023
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An…

  • CVE-2023-23591MedApr 12, 2023
    risk 0.32cvss 4.9epss 0.01

    The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.

  • CVE-2022-0718MedAug 29, 2022
    risk 0.32cvss 4.9epss 0.01

    A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.

  • CVE-2021-32570MedAug 26, 2022
    risk 0.32cvss 4.9epss 0.01

    In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized…

  • CVE-2022-20768MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain…

  • CVE-2022-22939MedFeb 4, 2022
    risk 0.32cvss 4.9epss 0.01

    VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in…

  • CVE-2021-23046MedSep 14, 2021
    risk 0.32cvss 4.9epss 0.01

    On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. Note: Software versions which have reached End of Technical…

  • CVE-2021-27022MedSep 7, 2021
    risk 0.32cvss 4.9epss 0.01

    A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).

  • CVE-2020-7021MedFeb 10, 2021
    risk 0.32cvss 4.9epss 0.01

    Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow…

  • CVE-2019-19150MedDec 23, 2019
    risk 0.32cvss 4.9epss 0.01

    On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session policy is attached to the virtual server with debug logging enabled.

  • CVE-2019-0380MedOct 8, 2019
    risk 0.32cvss 4.9epss 0.01

    Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.

  • CVE-2019-1961MedAug 8, 2019
    risk 0.32cvss 4.9epss 0.02

    A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to the improper input validation of tar packages…

  • CVE-2017-16946MedNov 25, 2017
    risk 0.32cvss 4.9epss 0.01

    The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.

  • CVE-2025-0976MedFeb 25, 2026
    risk 0.31cvss 4.7epss 0.00

    Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00.

  • CVE-2026-1622MedFeb 4, 2026
    risk 0.31cvss epss 0.00

    Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files. The "obfuscate_literals" option in the query logs does not redact error information,…

  • CVE-2026-22798MedJan 12, 2026
    risk 0.31cvss 5.9epss 0.00

    hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API…

  • CVE-2025-57813MedAug 26, 2025
    risk 0.31cvss 5.9epss 0.00

    traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, such as OAuth tokens, are recorded in log files when an error occurs during the execution of an SQL query. An attacker could…

  • CVE-2025-38745MedAug 14, 2025
    risk 0.31cvss 4.8epss 0.00

    Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backup and Restore. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information…