VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 42 of 60
  • CVE-2024-0935MedFeb 1, 2024
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024

  • CVE-2024-23840MedJan 30, 2024
    risk 0.29cvss 5.5epss 0.00

    GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.

  • CVE-2023-0436MedNov 7, 2023
    risk 0.29cvss 4.5epss 0.01

    The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. …

  • CVE-2023-21387MedOct 30, 2023
    risk 0.29cvss 4.4epss 0.00

    In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40425MedOct 25, 2023
    risk 0.29cvss 4.4epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14, macOS Monterey 12.7.1. An app with root privileges may be able to access private information.

  • CVE-2023-45825MedOct 19, 2023
    risk 0.29cvss 5.5epss 0.00

    ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custom credentials object (implementation of interface Credentials it may leak into logs. This happens because this object could be serialized into an error message…

  • CVE-2023-40682MedOct 13, 2023
    risk 0.29cvss 4.4epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833.

  • CVE-2023-39447MedOct 10, 2023
    risk 0.29cvss 4.4epss 0.00

    When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2023-30721MedSep 6, 2023
    risk 0.29cvss 4.4epss 0.00

    Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.

  • CVE-2023-4108MedAug 11, 2023
    risk 0.29cvss 4.5epss 0.01

    Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

  • CVE-2023-36494MedAug 2, 2023
    risk 0.29cvss 4.4epss 0.00

    Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2023-31207MedMay 2, 2023
    risk 0.29cvss 4.4epss 0.00

    Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.

  • CVE-2023-29471MedApr 27, 2023
    risk 0.29cvss 5.5epss 0.00

    Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.

  • CVE-2021-3684MedMar 24, 2023
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the…

  • CVE-2023-21435MedFeb 9, 2023
    risk 0.29cvss 4.4epss 0.00

    Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.

  • CVE-2022-4858MedDec 30, 2022
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.

  • CVE-2022-39897MedDec 8, 2022
    risk 0.29cvss 4.4epss 0.00

    Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.

  • CVE-2022-40979MedSep 23, 2022
    risk 0.29cvss 4.4epss 0.00

    In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable

  • CVE-2022-29928MedMay 12, 2022
    risk 0.29cvss 4.4epss 0.00

    In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible

  • CVE-2022-29810MedApr 27, 2022
    risk 0.29cvss 5.5epss 0.00

    The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.