VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 41 of 60
  • CVE-2025-14010MedDec 4, 2025
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve…

  • CVE-2025-40603MedOct 31, 2025
    risk 0.29cvss 4.5epss 0.00

    A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.

  • CVE-2025-46752MedOct 16, 2025
    risk 0.29cvss 4.4epss 0.00

    A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code.

  • CVE-2025-43485MedJul 23, 2025
    risk 0.29cvss 4.5epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the latest software update.

  • CVE-2025-6392MedJul 10, 2025
    risk 0.29cvss 4.4epss 0.00

    Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only…

  • CVE-2025-6711MedJul 7, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 versions prior to 8.0.5, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB…

  • CVE-2025-48374MedMay 22, 2025
    risk 0.29cvss epss 0.00

    zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f), when using Keycloak as an oidc provider, the clientsecret gets printed into…

  • CVE-2024-7577MedMar 29, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.

  • CVE-2025-23413MedFeb 5, 2025
    risk 0.29cvss 4.4epss 0.00

    When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2022-43933MedNov 21, 2024
    risk 0.29cvss 4.4epss 0.00

    An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include…

  • CVE-2024-51752MedNov 5, 2024
    risk 0.29cvss 5.5epss 0.00

    The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been…

  • CVE-2024-49750MedOct 24, 2024
    risk 0.29cvss 5.5epss 0.00

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector could have logged Duo…

  • CVE-2024-38862MedOct 14, 2024
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to administrators.

  • CVE-2023-46175MedSep 26, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user.

  • CVE-2024-8775MedSep 14, 2024
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter,…

  • CVE-2024-42344MedSep 10, 2024
    risk 0.29cvss 4.4epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an authenticated attacker to…

  • CVE-2024-5557MedJun 12, 2024
    risk 0.29cvss 4.5epss 0.00

    CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.

  • CVE-2024-34353MedMay 14, 2024
    risk 0.29cvss 5.5epss 0.00

    The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's…

  • CVE-2023-6833MedApr 23, 2024
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 11.0.1.

  • CVE-2024-1141MedFeb 1, 2024
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.