VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 50 of 63
  • CVE-2024-7586MedJun 20, 2025
    risk 0.27cvss 4.1epss 0.00

    An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

  • CVE-2024-9621MedOct 8, 2024
    risk 0.27cvss 5.3epss 0.01

    A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and…

  • CVE-2024-41719MedAug 14, 2024
    risk 0.27cvss 4.2epss 0.00

    When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2024-40636MedJul 17, 2024
    risk 0.27cvss 5.3epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka…

  • CVE-2024-0912MedJun 6, 2024
    risk 0.27cvss 4.2epss 0.00

    Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions

  • CVE-2023-1904MedDec 14, 2023
    risk 0.27cvss 4.2epss 0.00

    In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

  • CVE-2023-31417MedOct 26, 2023
    risk 0.27cvss 4.1epss 0.00

    Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that this filtering was not applied when requests to Elasticsearch use certain deprecated URIs for APIs. The impact of this flaw is that sensitive information…

  • CVE-2021-39011MedJan 20, 2023
    risk 0.27cvss 4.2epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645.

  • CVE-2022-27895MedNov 15, 2022
    risk 0.27cvss 4.2epss 0.00

    Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions earlier than 1.785.0. Upgrade to Build2 version 1.785.0 or greater.

  • CVE-2022-27896MedNov 14, 2022
    risk 0.27cvss 4.2epss 0.00

    Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python code being run. These service logs included the Foundry token that represents the Code-Workbooks…

  • CVE-2022-27893MedNov 4, 2022
    risk 0.27cvss 4.2epss 0.00

    The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0.

  • CVE-2022-36321MedJul 20, 2022
    risk 0.27cvss 4.1epss 0.02

    In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases

  • CVE-2022-2394MedJul 19, 2022
    risk 0.27cvss 4.1epss 0.01

    Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.

  • CVE-2018-1788MedNov 2, 2018
    risk 0.27cvss 4.1epss 0.00

    IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.

  • CVE-2026-27900MedFeb 26, 2026
    risk 0.26cvss 5.0epss 0.00

    The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by default. This issue is exposed when…

  • CVE-2025-24884MedJan 29, 2025
    risk 0.26cvss —epss 0.00

    kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is…

  • CVE-2024-12292MedDec 12, 2024
    risk 0.26cvss 4.0epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

  • CVE-2024-51528MedNov 5, 2024
    risk 0.26cvss 4.0epss 0.00

    Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-31216MedMay 15, 2024
    risk 0.26cvss 5.1epss 0.00

    The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps…

  • CVE-2023-50951MedFeb 17, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.