VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 46 of 63
  • CVE-2021-25284MedFeb 27, 2021
    risk 0.29cvss 4.4epss 0.01

    An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.

  • CVE-2021-21722MedJan 14, 2021
    risk 0.29cvss 4.4epss 0.00

    A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A…

  • CVE-2021-3032MedJan 13, 2021
    risk 0.29cvss 4.4epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged information…

  • CVE-2020-0476MedDec 15, 2020
    risk 0.29cvss 4.4epss 0.00

    In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-10763MedNov 24, 2020
    risk 0.29cvss 5.5epss 0.00

    An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.

  • CVE-2020-14332MedSep 11, 2020
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is…

  • CVE-2020-3541MedSep 4, 2020
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The vulnerability is…

  • CVE-2020-4498MedJul 27, 2020
    risk 0.29cvss 4.4epss 0.00

    IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files. IBM X-Force ID: 182118.

  • CVE-2020-0018MedFeb 13, 2020
    risk 0.29cvss 4.4epss 0.00

    In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lead to local disclosure of user input with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-5225MedJan 24, 2020
    risk 0.29cvss 4.4epss 0.01

    Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the system administrator, did not properly sanitize the report identifier obtained from the request. This allows an attacker, under…

  • CVE-2019-14858MedOct 14, 2019
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub…

  • CVE-2019-4572MedOct 14, 2019
    risk 0.29cvss 4.4epss 0.00

    IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine. IBM X-Force ID: 166798.

  • CVE-2019-6648MedSep 4, 2019
    risk 0.29cvss 4.4epss 0.00

    On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by an AS3 Declaration.

  • CVE-2019-10367MedAug 7, 2019
    risk 0.29cvss 5.5epss 0.00

    Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.

  • CVE-2019-4284MedAug 5, 2019
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to the system as another user. IBM X-Force ID: 160512.

  • CVE-2019-10364MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.

  • CVE-2019-10345MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

  • CVE-2019-4225MedJun 26, 2019
    risk 0.29cvss 4.4epss 0.00

    IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 159242.

  • CVE-2018-16856MedMar 26, 2019
    risk 0.29cvss 5.5epss 0.01

    In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in…

  • CVE-2018-2440MedJul 10, 2018
    risk 0.29cvss 4.4epss 0.00

    Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.