VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 52 of 60
  • CVE-2024-39460MedJun 26, 2024
    risk 0.21cvss 4.3epss 0.00

    Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.

  • CVE-2023-27502LowMar 14, 2024
    risk 0.21cvss 3.3epss 0.00

    Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2316.5.1.2 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2024-27097MedMar 13, 2024
    risk 0.21cvss 4.3epss 0.00

    A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting false log entries or corrupt the log file format. This has been fixed in the CKAN versions 2.9.11 and 2.10.4. Users are…

  • CVE-2024-23242LowMar 8, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.

  • CVE-2024-24939LowFeb 6, 2024
    risk 0.21cvss 3.3epss 0.00

    In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

  • CVE-2024-23210LowJan 23, 2024
    risk 0.21cvss 3.3epss 0.00

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to view a user's phone number in system logs.

  • CVE-2023-6287LowNov 27, 2023
    risk 0.21cvss 3.3epss 0.00

    Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.

  • CVE-2023-42857LowOct 25, 2023
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to access sensitive user data.

  • CVE-2023-40405LowOct 25, 2023
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.1. An app may be able to read sensitive location information.

  • CVE-2023-40442LowSep 12, 2023
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8. An app may be able to read sensitive location information.

  • CVE-2023-40392LowSep 6, 2023
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.5. An app may be able to read sensitive location information.

  • CVE-2023-26207LowJun 13, 2023
    risk 0.21cvss 3.3epss 0.01

    An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain passwords in plain text.

  • CVE-2023-28351LowMay 31, 2023
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially…

  • CVE-2023-31413LowMay 4, 2023
    risk 0.21cvss 3.3epss 0.00

    Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.

  • CVE-2022-48435LowApr 4, 2023
    risk 0.21cvss 3.3epss 0.00

    In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file

  • CVE-2023-23505LowFeb 27, 2023
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, iOS 15.7.3 and iPadOS 15.7.3, iOS 16.3 and iPadOS 16.3. An app may be able to access…

  • CVE-2022-39893LowNov 9, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.

  • CVE-2022-38133LowAug 10, 2022
    risk 0.21cvss 3.2epss 0.00

    In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases

  • CVE-2022-31186LowAug 1, 2022
    risk 0.21cvss 3.3epss 0.00

    NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulnerability in `next-auth` before `v4.10.2` and `v3.29.9` allows an attacker with log access privilege to obtain excessive information such as an identity…

  • CVE-2022-33697LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.