CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,196)
page 42 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-0935 | Med | 0.29 | 4.4 | 0.00 | Feb 1, 2024 | Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024 | ||
| CVE-2024-23840 | Med | 0.29 | 5.5 | 0.00 | Jan 30, 2024 | GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0. | ||
| CVE-2023-0436 | Med | 0.29 | 4.5 | 0.01 | Nov 7, 2023 | The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. … | ||
| CVE-2023-21387 | Med | 0.29 | 4.4 | 0.00 | Oct 30, 2023 | In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40425 | Med | 0.29 | 4.4 | 0.00 | Oct 25, 2023 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14, macOS Monterey 12.7.1. An app with root privileges may be able to access private information. | ||
| CVE-2023-45825 | Med | 0.29 | 5.5 | 0.00 | Oct 19, 2023 | ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custom credentials object (implementation of interface Credentials it may leak into logs. This happens because this object could be serialized into an error message… | ||
| CVE-2023-40682 | Med | 0.29 | 4.4 | 0.00 | Oct 13, 2023 | IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833. | ||
| CVE-2023-39447 | Med | 0.29 | 4.4 | 0.00 | Oct 10, 2023 | When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||
| CVE-2023-30721 | Med | 0.29 | 4.4 | 0.00 | Sep 6, 2023 | Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log. | ||
| CVE-2023-4108 | Med | 0.29 | 4.5 | 0.01 | Aug 11, 2023 | Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged | ||
| CVE-2023-36494 | Med | 0.29 | 4.4 | 0.00 | Aug 2, 2023 | Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||
| CVE-2023-31207 | Med | 0.29 | 4.4 | 0.00 | May 2, 2023 | Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log. | ||
| CVE-2023-29471 | Med | 0.29 | 5.5 | 0.00 | Apr 27, 2023 | Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor. | ||
| CVE-2021-3684 | Med | 0.29 | 5.5 | 0.00 | Mar 24, 2023 | A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the… | ||
| CVE-2023-21435 | Med | 0.29 | 4.4 | 0.00 | Feb 9, 2023 | Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log. | ||
| CVE-2022-4858 | Med | 0.29 | 4.4 | 0.00 | Dec 30, 2022 | Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set. | ||
| CVE-2022-39897 | Med | 0.29 | 4.4 | 0.00 | Dec 8, 2022 | Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log. | ||
| CVE-2022-40979 | Med | 0.29 | 4.4 | 0.00 | Sep 23, 2022 | In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable | ||
| CVE-2022-29928 | Med | 0.29 | 4.4 | 0.00 | May 12, 2022 | In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible | ||
| CVE-2022-29810 | Med | 0.29 | 5.5 | 0.00 | Apr 27, 2022 | The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter. |
- risk 0.29cvss 4.4epss 0.00
Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024
- risk 0.29cvss 5.5epss 0.00
GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.
- risk 0.29cvss 4.5epss 0.01
The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. …
- risk 0.29cvss 4.4epss 0.00
In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
- risk 0.29cvss 4.4epss 0.00
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14, macOS Monterey 12.7.1. An app with root privileges may be able to access private information.
- risk 0.29cvss 5.5epss 0.00
ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custom credentials object (implementation of interface Credentials it may leak into logs. This happens because this object could be serialized into an error message…
- risk 0.29cvss 4.4epss 0.00
IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833.
- risk 0.29cvss 4.4epss 0.00
When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- risk 0.29cvss 4.4epss 0.00
Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.
- risk 0.29cvss 4.5epss 0.01
Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged
- risk 0.29cvss 4.4epss 0.00
Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- risk 0.29cvss 4.4epss 0.00
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
- risk 0.29cvss 5.5epss 0.00
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
- risk 0.29cvss 5.5epss 0.00
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the…
- risk 0.29cvss 4.4epss 0.00
Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.
- risk 0.29cvss 4.4epss 0.00
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
- risk 0.29cvss 4.4epss 0.00
Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.
- risk 0.29cvss 4.4epss 0.00
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
- risk 0.29cvss 4.4epss 0.00
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
- risk 0.29cvss 5.5epss 0.00
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.