CWE-532
Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-215
CVEs mapped to this weakness (1,196)
page 53 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-33688 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log. | ||
| CVE-2022-33687 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log. | ||
| CVE-2022-30742 | Low | 0.21 | 3.3 | 0.00 | Jun 7, 2022 | Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log. | ||
| CVE-2022-30741 | Low | 0.21 | 3.3 | 0.00 | Jun 7, 2022 | Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log. | ||
| CVE-2021-39739 | Low | 0.21 | 3.3 | 0.00 | Mar 30, 2022 | In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-0652 | Low | 0.21 | 3.3 | 0.00 | Mar 22, 2022 | Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710. | ||
| CVE-2022-0021 | Low | 0.21 | 3.3 | 0.00 | Feb 10, 2022 | An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect… | ||
| CVE-2022-0338 | Med | 0.21 | 4.3 | 0.01 | Jan 25, 2022 | Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3. | ||
| CVE-2021-26908 | Low | 0.21 | 3.3 | 0.00 | Apr 23, 2021 | Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent. | ||
| CVE-2020-2048 | Low | 0.21 | 3.3 | 0.00 | Nov 12, 2020 | An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier… | ||
| CVE-2019-20625 | Low | 0.21 | 3.3 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019). | ||
| CVE-2019-9277 | Low | 0.21 | 3.3 | 0.00 | Sep 27, 2019 | In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:… | ||
| CVE-2017-18423 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273). | ||
| CVE-2019-4296 | Low | 0.21 | 3.3 | 0.00 | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759. | ||
| CVE-2018-10889 | Med | 0.21 | 4.3 | 0.02 | Jul 10, 2018 | A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester. | ||
| CVE-2017-9271 | Low | 0.21 | 3.3 | 0.00 | Mar 1, 2018 | The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used. | ||
| CVE-2018-5693 | Low | 0.21 | 3.3 | 0.00 | Jan 14, 2018 | The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog. | ||
| CVE-2016-0296 | Low | 0.21 | 3.3 | 0.00 | Feb 1, 2017 | IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user. | ||
| CVE-2016-5432 | Low | 0.21 | 3.3 | 0.00 | Oct 3, 2016 | The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files. | ||
| CVE-2025-53885 | Med | 0.20 | 4.2 | 0.00 | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console"… |
- risk 0.21cvss 3.3epss 0.00
Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
- risk 0.21cvss 3.3epss 0.00
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.
- risk 0.21cvss 3.3epss 0.00
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log.
- risk 0.21cvss 3.3epss 0.00
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.21cvss 3.3epss 0.00
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
- risk 0.21cvss 3.3epss 0.00
An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect…
- risk 0.21cvss 4.3epss 0.01
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
- risk 0.21cvss 3.3epss 0.00
Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.
- risk 0.21cvss 3.3epss 0.00
An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier…
- risk 0.21cvss 3.3epss 0.00
An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019).
- risk 0.21cvss 3.3epss 0.00
In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:…
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
- risk 0.21cvss 3.3epss 0.00
IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759.
- risk 0.21cvss 4.3epss 0.02
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.
- risk 0.21cvss 3.3epss 0.00
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
- risk 0.21cvss 3.3epss 0.00
The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog.
- risk 0.21cvss 3.3epss 0.00
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
- risk 0.21cvss 3.3epss 0.00
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
- risk 0.20cvss 4.2epss 0.00
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console"…