VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 51 of 63
  • CVE-2023-48708MedNov 24, 2023
    risk 0.26cvss 5.0epss 0.01

    CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw…

  • CVE-2022-39874MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

  • CVE-2022-29071MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP…

  • CVE-2022-27549MedJul 6, 2022
    risk 0.26cvss 4.0epss 0.00

    HCL Launch may store certain data for recurring activities in a plain text format.

  • CVE-2022-30733MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.01

    Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

  • CVE-2020-26416MedDec 11, 2020
    risk 0.26cvss 4.0epss 0.00

    Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

  • CVE-2020-14330MedSep 11, 2020
    risk 0.26cvss 5.0epss 0.01

    An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other…

  • CVE-2020-3930MedJun 12, 2020
    risk 0.26cvss 4.0epss 0.00

    GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs.

  • CVE-2020-1698MedMay 11, 2020
    risk 0.26cvss 5.0epss 0.00

    A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.

  • CVE-2020-1753MedMar 16, 2020
    risk 0.26cvss 5.0epss 0.01

    A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are…

  • CVE-2018-20105MedJan 27, 2020
    risk 0.26cvss 4.0epss 0.00

    A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions…

  • CVE-2017-1733MedApr 4, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.

  • CVE-2026-34164MedApr 16, 2026
    risk 0.25cvss 4.9epss 0.00

    Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at INFO level. Inbox messages can contain highly sensitive information including personal data…

  • CVE-2025-62705MedOct 22, 2025
    risk 0.25cvss 4.9epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use…

  • CVE-2025-3456LowAug 25, 2025
    risk 0.25cvss 3.8epss 0.00

    On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be…

  • CVE-2025-48709LowAug 7, 2025
    risk 0.25cvss 3.8epss 0.00

    BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a…

  • CVE-2024-52067MedNov 21, 2024
    risk 0.25cvss 4.9epss 0.01

    Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow…

  • CVE-2024-38460MedJun 16, 2024
    risk 0.25cvss 4.9epss 0.00

    In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).

  • CVE-2023-3363LowJul 13, 2023
    risk 0.25cvss 3.9epss 0.00

    An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.

  • CVE-2022-43772LowApr 3, 2023
    risk 0.25cvss 3.8epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs.