VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 54 of 63
  • CVE-2026-20646LowFeb 11, 2026
    risk 0.21cvss 3.3epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information.

  • CVE-2025-46277LowDec 17, 2025
    risk 0.21cvss 3.3epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, watchOS 26.2. An app may be able to access a user’s Safari history.

  • CVE-2025-43517LowDec 12, 2025
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access protected user data.

  • CVE-2024-58269MedOct 29, 2025
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entity with access to Rancher audit logs.

  • CVE-2025-11248LowOct 27, 2025
    risk 0.21cvss 3.2epss 0.00

    ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.

  • CVE-2025-36144LowSep 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2025-24520LowAug 12, 2025
    risk 0.21cvss 3.3epss 0.00

    Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2514.7.16.0 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2025-46614LowApr 28, 2025
    risk 0.21cvss 3.3epss 0.00

    In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.

  • CVE-2025-32054LowApr 3, 2025
    risk 0.21cvss 3.3epss 0.00

    In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file

  • CVE-2024-45674LowFeb 22, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores potentially sensitive information in log files that could be read by a…

  • CVE-2025-24145LowJan 27, 2025
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An app may be able to view a contact's phone number in system logs.

  • CVE-2024-27849LowOct 28, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be able to read sensitive location information.

  • CVE-2024-40791LowSep 17, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to access information about a user's contacts.

  • CVE-2024-40096LowAug 5, 2024
    risk 0.21cvss 3.3epss 0.00

    The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.

  • CVE-2024-39460MedJun 26, 2024
    risk 0.21cvss 4.3epss 0.00

    Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.

  • CVE-2023-27502LowMar 14, 2024
    risk 0.21cvss 3.3epss 0.00

    Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2316.5.1.2 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2024-27097MedMar 13, 2024
    risk 0.21cvss 4.3epss 0.00

    A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting false log entries or corrupt the log file format. This has been fixed in the CKAN versions 2.9.11 and 2.10.4. Users are…

  • CVE-2024-23242LowMar 8, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.

  • CVE-2024-24939LowFeb 6, 2024
    risk 0.21cvss 3.3epss 0.00

    In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

  • CVE-2024-23210LowJan 23, 2024
    risk 0.21cvss 3.3epss 0.00

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to view a user's phone number in system logs.