VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 55 of 60
  • CVE-2024-23760LowFeb 12, 2024
    risk 0.18cvss 2.7epss 0.00

    Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the webroot.

  • CVE-2022-36877LowSep 9, 2022
    risk 0.18cvss 2.8epss 0.00

    Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.

  • CVE-2019-4706LowJul 1, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. IBM X-Force ID: 172016.

  • CVE-2017-18426LowAug 2, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).

  • CVE-2022-1157LowApr 11, 2022
    risk 0.17cvss 2.6epss 0.01

    Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

  • CVE-2026-44969LowJul 16, 2026
    risk 0.16cvss 2.5epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote…

  • CVE-2025-4234LowSep 12, 2025
    risk 0.16cvss epss 0.00

    A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This…

  • CVE-2025-52580LowJul 22, 2025
    risk 0.16cvss 2.4epss 0.00

    Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploited, sensitive user information may be exposed to an attacker who has access to the application logs.

  • CVE-2022-39043LowMar 27, 2023
    risk 0.16cvss 2.4epss 0.00

    Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physical attacker can access these files to acquire partial user information such as personal contacts.

  • CVE-2021-0991LowDec 15, 2021
    risk 0.16cvss 2.4epss 0.00

    In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not…

  • CVE-2017-18412LowAug 2, 2019
    risk 0.16cvss 2.5epss 0.00

    cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).

  • CVE-2025-46777LowMay 28, 2025
    risk 0.15cvss 2.3epss 0.00

    A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view encrypted secrets via the FortiPortal…

  • CVE-2023-45585LowNov 14, 2023
    risk 0.15cvss 2.3epss 0.00

    An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below,…

  • CVE-2021-29759LowJul 7, 2021
    risk 0.15cvss 2.3epss 0.00

    IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, and 1.3 could allow a privileged user to obtain sensitive information from internal log files. IBM X-Force ID: 202212.

  • CVE-2021-3037LowApr 20, 2021
    risk 0.15cvss 2.3epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to…

  • CVE-2018-1350LowMar 26, 2018
    risk 0.15cvss 2.3epss 0.01

    The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

  • CVE-2018-1349LowMar 26, 2018
    risk 0.15cvss 2.3epss 0.01

    The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

  • CVE-2026-25211LowJan 30, 2026
    risk 0.14cvss 3.2epss 0.00

    Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.

  • CVE-2025-13321LowDec 17, 2025
    risk 0.14cvss 3.3epss 0.00

    Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.

  • CVE-2025-27496LowMar 13, 2025
    risk 0.14cvss 3.3epss 0.00

    Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the…