CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,256)
page 47 of 63| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-1795 | Med | 0.29 | 4.4 | 0.00 | Jul 6, 2018 | IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042. | ||
| CVE-2026-76374 | Med | 0.28 | 4.3 | 0.00 | Aug 19, 2026 | In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more… | ||
| CVE-2026-46358 | Med | 0.28 | — | 0.00 | Aug 7, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires… | ||
| CVE-2026-54236 | Med | 0.28 | 5.3 | 0.01 | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper that strips object-repr memory addresses from error messages before they reach the client, is incomplete: several… | ||
| CVE-2026-33558 | Med | 0.28 | 5.3 | 0.01 | Apr 20, 2026 | Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the… | ||
| CVE-2026-1265 | Med | 0.28 | 4.3 | 0.00 | Mar 3, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file. | ||
| CVE-2025-54971 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2025 | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all versions, FortiADC 6.2 all versions may allow an admin with read-only permission to get the external… | ||
| CVE-2025-36599 | Med | 0.28 | 4.3 | 0.00 | Jul 9, 2025 | Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The… | ||
| CVE-2025-46432 | Med | 0.28 | 4.3 | 0.01 | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs | ||
| CVE-2025-31139 | Med | 0.28 | 4.3 | 0.01 | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log | ||
| CVE-2024-13416 | — | Med | 0.28 | 4.3 | 0.00 | Feb 6, 2025 | Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has released an updated version 2.46 of 2N OS, where this vulnerability is mitigated. It is recommended that all customers update their devices to… | |
| CVE-2023-38271 | Med | 0.28 | 4.3 | 0.00 | Jan 25, 2025 | IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obtain sensitive information from log files. | ||
| CVE-2024-55578 | Med | 0.28 | 4.3 | 0.00 | Dec 9, 2024 | Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files. | ||
| CVE-2024-0006 | Med | 0.28 | — | 0.00 | Jul 19, 2024 | Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access. | ||
| CVE-2024-40598 | Med | 0.28 | 4.3 | 0.00 | Jul 7, 2024 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.) | ||
| CVE-2024-40596 | Med | 0.28 | 4.3 | 0.00 | Jul 7, 2024 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.) | ||
| CVE-2024-22339 | Med | 0.28 | 4.3 | 0.00 | Apr 12, 2024 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from some log files. IBM… | ||
| CVE-2023-46171 | Med | 0.28 | 4.3 | 0.00 | Mar 7, 2024 | IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to view sensitive log information after enumerating filenames. IBM X-Force ID: 269408. | ||
| CVE-2023-50740 | Med | 0.28 | 5.3 | 0.01 | Mar 6, 2024 | In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend users upgrade the version of Linkis to version 1.5.0 | ||
| CVE-2024-23677 | Med | 0.28 | 4.3 | 0.00 | Jan 22, 2024 | In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file. |
- risk 0.29cvss 4.4epss 0.00
IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.
- risk 0.28cvss 4.3epss 0.00
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more…
- risk 0.28cvss —epss 0.00
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires…
- risk 0.28cvss 5.3epss 0.01
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper that strips object-repr memory addresses from error messages before they reach the client, is incomplete: several…
- risk 0.28cvss 5.3epss 0.01
Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the…
- risk 0.28cvss 4.3epss 0.00
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.
- risk 0.28cvss 4.3epss 0.00
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all versions, FortiADC 6.2 all versions may allow an admin with read-only permission to get the external…
- risk 0.28cvss 4.3epss 0.00
Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
- risk 0.28cvss 4.3epss 0.00
Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has released an updated version 2.46 of 2N OS, where this vulnerability is mitigated. It is recommended that all customers update their devices to…
- risk 0.28cvss 4.3epss 0.00
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obtain sensitive information from log files.
- risk 0.28cvss 4.3epss 0.00
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.
- risk 0.28cvss —epss 0.00
Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.
- risk 0.28cvss 4.3epss 0.00
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)
- risk 0.28cvss 4.3epss 0.00
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.)
- risk 0.28cvss 4.3epss 0.00
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from some log files. IBM…
- risk 0.28cvss 4.3epss 0.00
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to view sensitive log information after enumerating filenames. IBM X-Force ID: 269408.
- risk 0.28cvss 5.3epss 0.01
In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend users upgrade the version of Linkis to version 1.5.0
- risk 0.28cvss 4.3epss 0.00
In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.