CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,256)
page 48 of 63| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38733 | Med | 0.28 | 4.3 | 0.00 | Aug 22, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293. | ||
| CVE-2023-38732 | Med | 0.28 | 4.3 | 0.01 | Aug 22, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive information from application logs. IBM X-Force ID: 262289. | ||
| CVE-2023-40338 | Med | 0.28 | 4.3 | 0.01 | Aug 16, 2023 | Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system. | ||
| CVE-2023-38067 | Med | 0.28 | 4.3 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log | ||
| CVE-2023-38064 | Med | 0.28 | 4.3 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log | ||
| CVE-2023-34223 | Med | 0.28 | 4.3 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases | ||
| CVE-2023-25687 | Med | 0.28 | 4.3 | 0.00 | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602. | ||
| CVE-2022-43954 | Med | 0.28 | 4.3 | 0.01 | Feb 16, 2023 | An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page. | ||
| CVE-2022-38756 | Med | 0.28 | 4.3 | 0.01 | Dec 16, 2022 | A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies. | ||
| CVE-2022-31684 | Med | 0.28 | 4.3 | 0.01 | Oct 19, 2022 | Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level… | ||
| CVE-2022-31674 | Med | 0.28 | 4.3 | 0.01 | Aug 10, 2022 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure. | ||
| CVE-2022-31047 | Med | 0.28 | 5.3 | 0.01 | Jun 14, 2022 | TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete… | ||
| CVE-2022-32254 | Med | 0.28 | 4.3 | 0.01 | Jun 14, 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an… | ||
| CVE-2022-20807 | Med | 0.28 | 4.3 | 0.01 | May 27, 2022 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For… | ||
| CVE-2022-20806 | Med | 0.28 | 4.3 | 0.01 | May 27, 2022 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For… | ||
| CVE-2022-20809 | Med | 0.28 | 4.3 | 0.01 | May 26, 2022 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For… | ||
| CVE-2022-26907 | Med | 0.28 | 5.3 | 0.02 | Apr 15, 2022 | Azure SDK for .NET Information Disclosure Vulnerability | ||
| CVE-2021-27019 | Med | 0.28 | 4.3 | 0.01 | Aug 30, 2021 | PuppetDB logging included potentially sensitive system information. | ||
| CVE-2021-26999 | Med | 0.28 | 4.3 | 0.01 | Aug 6, 2021 | NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using… | ||
| CVE-2021-26998 | Med | 0.28 | 4.3 | 0.01 | Aug 6, 2021 | NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to… |
- risk 0.28cvss 4.3epss 0.00
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293.
- risk 0.28cvss 4.3epss 0.01
IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive information from application logs. IBM X-Force ID: 262289.
- risk 0.28cvss 4.3epss 0.01
Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
- risk 0.28cvss 4.3epss 0.00
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
- risk 0.28cvss 4.3epss 0.01
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
- risk 0.28cvss 4.3epss 0.01
A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.
- risk 0.28cvss 4.3epss 0.01
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level…
- risk 0.28cvss 4.3epss 0.01
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
- risk 0.28cvss 5.3epss 0.01
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete…
- risk 0.28cvss 4.3epss 0.01
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an…
- risk 0.28cvss 4.3epss 0.01
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For…
- risk 0.28cvss 4.3epss 0.01
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For…
- risk 0.28cvss 4.3epss 0.01
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For…
- risk 0.28cvss 5.3epss 0.02
Azure SDK for .NET Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
PuppetDB logging included potentially sensitive system information.
- risk 0.28cvss 4.3epss 0.01
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using…
- risk 0.28cvss 4.3epss 0.01
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to…