VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 43 of 60
  • CVE-2021-39715MedMar 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-27195MedMar 15, 2022
    risk 0.29cvss 5.5epss 0.00

    Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by…

  • CVE-2022-20630MedFeb 10, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative…

  • CVE-2021-27026MedNov 18, 2021
    risk 0.29cvss 4.4epss 0.00

    A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged

  • CVE-2021-0148MedNov 17, 2021
    risk 0.29cvss 4.4epss 0.00

    Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2021-39913MedNov 5, 2021
    risk 0.29cvss 4.4epss 0.00

    Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system…

  • CVE-2021-0549MedJun 22, 2021
    risk 0.29cvss 4.4epss 0.00

    In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-22219MedJun 8, 2021
    risk 0.29cvss 4.4epss 0.01

    All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was…

  • CVE-2021-3425MedJun 1, 2021
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ 7 are vulnerable.

  • CVE-2021-20191MedMay 26, 2021
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this…

  • CVE-2021-20178MedMay 26, 2021
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat…

  • CVE-2021-3036MedApr 20, 2021
    risk 0.29cvss 4.4epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that…

  • CVE-2021-22310MedMar 22, 2021
    risk 0.29cvss 4.4epss 0.00

    There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected…

  • CVE-2021-25284MedFeb 27, 2021
    risk 0.29cvss 4.4epss 0.01

    An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.

  • CVE-2021-21722MedJan 14, 2021
    risk 0.29cvss 4.4epss 0.00

    A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A…

  • CVE-2021-3032MedJan 13, 2021
    risk 0.29cvss 4.4epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged information…

  • CVE-2020-0476MedDec 15, 2020
    risk 0.29cvss 4.4epss 0.00

    In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-10763MedNov 24, 2020
    risk 0.29cvss 5.5epss 0.00

    An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.

  • CVE-2020-14332MedSep 11, 2020
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is…

  • CVE-2020-3541MedSep 4, 2020
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The vulnerability is…