VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 44 of 63
  • CVE-2023-46175MedSep 26, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user.

  • CVE-2024-8775MedSep 14, 2024
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter,…

  • CVE-2024-42344MedSep 10, 2024
    risk 0.29cvss 4.4epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an authenticated attacker to…

  • CVE-2024-5557MedJun 12, 2024
    risk 0.29cvss 4.5epss 0.00

    CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.

  • CVE-2024-34353MedMay 14, 2024
    risk 0.29cvss 5.5epss 0.00

    The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's…

  • CVE-2023-6833MedApr 23, 2024
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 11.0.1.

  • CVE-2024-1141MedFeb 1, 2024
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.

  • CVE-2024-0935MedFeb 1, 2024
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024

  • CVE-2024-23840MedJan 30, 2024
    risk 0.29cvss 5.5epss 0.00

    GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.

  • CVE-2023-0436MedNov 7, 2023
    risk 0.29cvss 4.5epss 0.01

    The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. …

  • CVE-2023-21387MedOct 30, 2023
    risk 0.29cvss 4.4epss 0.00

    In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40425MedOct 25, 2023
    risk 0.29cvss 4.4epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14, macOS Monterey 12.7.1. An app with root privileges may be able to access private information.

  • CVE-2023-45825MedOct 19, 2023
    risk 0.29cvss 5.5epss 0.00

    ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custom credentials object (implementation of interface Credentials it may leak into logs. This happens because this object could be serialized into an error message…

  • CVE-2023-40682MedOct 13, 2023
    risk 0.29cvss 4.4epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833.

  • CVE-2023-39447MedOct 10, 2023
    risk 0.29cvss 4.4epss 0.00

    When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2023-30721MedSep 6, 2023
    risk 0.29cvss 4.4epss 0.00

    Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.

  • CVE-2023-4108MedAug 11, 2023
    risk 0.29cvss 4.5epss 0.01

    Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

  • CVE-2023-36494MedAug 2, 2023
    risk 0.29cvss 4.4epss 0.00

    Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2023-31207MedMay 2, 2023
    risk 0.29cvss 4.4epss 0.00

    Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.

  • CVE-2023-29471MedApr 27, 2023
    risk 0.29cvss 5.5epss 0.00

    Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.