VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 45 of 63
  • CVE-2021-3684MedMar 24, 2023
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the…

  • CVE-2023-21435MedFeb 9, 2023
    risk 0.29cvss 4.4epss 0.00

    Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.

  • CVE-2022-4858MedDec 30, 2022
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.

  • CVE-2022-39897MedDec 8, 2022
    risk 0.29cvss 4.4epss 0.00

    Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.

  • CVE-2022-40979MedSep 23, 2022
    risk 0.29cvss 4.4epss 0.00

    In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable

  • CVE-2022-29928MedMay 12, 2022
    risk 0.29cvss 4.4epss 0.00

    In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible

  • CVE-2022-29810MedApr 27, 2022
    risk 0.29cvss 5.5epss 0.00

    The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.

  • CVE-2021-39715MedMar 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-27195MedMar 15, 2022
    risk 0.29cvss 5.5epss 0.00

    Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by…

  • CVE-2022-20630MedFeb 10, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative…

  • CVE-2021-27026MedNov 18, 2021
    risk 0.29cvss 4.4epss 0.00

    A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged

  • CVE-2021-0148MedNov 17, 2021
    risk 0.29cvss 4.4epss 0.00

    Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2021-39913MedNov 5, 2021
    risk 0.29cvss 4.4epss 0.00

    Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system…

  • CVE-2021-0549MedJun 22, 2021
    risk 0.29cvss 4.4epss 0.00

    In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-22219MedJun 8, 2021
    risk 0.29cvss 4.4epss 0.01

    All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was…

  • CVE-2021-3425MedJun 1, 2021
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ 7 are vulnerable.

  • CVE-2021-20191MedMay 26, 2021
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this…

  • CVE-2021-20178MedMay 26, 2021
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat…

  • CVE-2021-3036MedApr 20, 2021
    risk 0.29cvss 4.4epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that…

  • CVE-2021-22310MedMar 22, 2021
    risk 0.29cvss 4.4epss 0.00

    There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected…