VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 48 of 60
  • CVE-2022-27896MedNov 14, 2022
    risk 0.27cvss 4.2epss 0.00

    Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python code being run. These service logs included the Foundry token that represents the Code-Workbooks…

  • CVE-2022-27893MedNov 4, 2022
    risk 0.27cvss 4.2epss 0.00

    The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0.

  • CVE-2022-36321MedJul 20, 2022
    risk 0.27cvss 4.1epss 0.02

    In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases

  • CVE-2022-2394MedJul 19, 2022
    risk 0.27cvss 4.1epss 0.01

    Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.

  • CVE-2018-1788MedNov 2, 2018
    risk 0.27cvss 4.1epss 0.00

    IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.

  • CVE-2026-27900MedFeb 26, 2026
    risk 0.26cvss 5.0epss 0.00

    The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by default. This issue is exposed when…

  • CVE-2025-24884MedJan 29, 2025
    risk 0.26cvss epss 0.00

    kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is…

  • CVE-2024-12292MedDec 12, 2024
    risk 0.26cvss 4.0epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

  • CVE-2024-51528MedNov 5, 2024
    risk 0.26cvss 4.0epss 0.00

    Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-31216MedMay 15, 2024
    risk 0.26cvss 5.1epss 0.00

    The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps…

  • CVE-2023-50951MedFeb 17, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.

  • CVE-2023-48708MedNov 24, 2023
    risk 0.26cvss 5.0epss 0.01

    CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw…

  • CVE-2022-39874MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

  • CVE-2022-29071MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP…

  • CVE-2022-27549MedJul 6, 2022
    risk 0.26cvss 4.0epss 0.00

    HCL Launch may store certain data for recurring activities in a plain text format.

  • CVE-2022-30733MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.01

    Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

  • CVE-2020-26416MedDec 11, 2020
    risk 0.26cvss 4.0epss 0.00

    Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

  • CVE-2020-14330MedSep 11, 2020
    risk 0.26cvss 5.0epss 0.01

    An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other…

  • CVE-2020-3930MedJun 12, 2020
    risk 0.26cvss 4.0epss 0.00

    GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs.

  • CVE-2020-1698MedMay 11, 2020
    risk 0.26cvss 5.0epss 0.00

    A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.