VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 56 of 63
  • CVE-2022-0021LowFeb 10, 2022
    risk 0.21cvss 3.3epss 0.00

    An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect…

  • CVE-2022-0338MedJan 25, 2022
    risk 0.21cvss 4.3epss 0.01

    Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.

  • CVE-2021-26908LowApr 23, 2021
    risk 0.21cvss 3.3epss 0.00

    Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.

  • CVE-2020-2048LowNov 12, 2020
    risk 0.21cvss 3.3epss 0.00

    An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier…

  • CVE-2019-20625LowMar 24, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019).

  • CVE-2019-9277LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:…

  • CVE-2017-18423LowAug 2, 2019
    risk 0.21cvss 3.3epss 0.00

    In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).

  • CVE-2019-4296LowJul 1, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759.

  • CVE-2018-10889MedJul 10, 2018
    risk 0.21cvss 4.3epss 0.02

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

  • CVE-2017-9271LowMar 1, 2018
    risk 0.21cvss 3.3epss 0.00

    The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.

  • CVE-2018-5693LowJan 14, 2018
    risk 0.21cvss 3.3epss 0.00

    The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog.

  • CVE-2016-0296LowFeb 1, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.

  • CVE-2016-5432LowOct 3, 2016
    risk 0.21cvss 3.3epss 0.00

    The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.

  • CVE-2026-73442LowSep 16, 2026
    risk 0.20cvss 3.0epss 0.00

    On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to…

  • CVE-2026-59302LowAug 27, 2026
    risk 0.20cvss 3.1epss 0.00

    Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

  • CVE-2026-59301LowAug 27, 2026
    risk 0.20cvss 3.1epss 0.00

    Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7

  • CVE-2026-59300LowAug 27, 2026
    risk 0.20cvss 3.1epss 0.00

    Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

  • CVE-2025-53885MedJul 15, 2025
    risk 0.20cvss 4.2epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console"…

  • CVE-2025-49846MedJul 3, 2025
    risk 0.20cvss —epss 0.00

    wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view port have been logged to the iOS system logs in clear text. Wire application logs created and managed by the application itself…

  • CVE-2025-22246LowMay 13, 2025
    risk 0.20cvss 3.0epss 0.00

    Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.