VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 56 of 60
  • CVE-2025-24034LowJan 23, 2025
    risk 0.14cvss 3.2epss 0.00

    Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to versions 0.7.15 and 0.8.3, Himmelblau is vulnerable to leaking credentials in debug logs. When debug logging is enabled, user access tokens are inadvertently…

  • CVE-2022-46647LowNov 14, 2023
    risk 0.14cvss 2.2epss 0.00

    Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2023-30618LowApr 21, 2023
    risk 0.14cvss 3.2epss 0.00

    Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform configuration and verify the resulting infrastructure systems with InSpec controls. Kitchen-Terraform v7.0.0 introduced a regression which caused all Terraform…

  • CVE-2019-10343LowJul 31, 2019
    risk 0.14cvss 3.3epss 0.00

    Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.

  • CVE-2026-29184LowMar 7, 2026
    risk 0.13cvss 2.0epss 0.00

    Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4.

  • CVE-2025-13611LowNov 26, 2025
    risk 0.13cvss 2.0epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

  • CVE-2025-43423LowNov 4, 2025
    risk 0.13cvss 2.0epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical access to an unlocked device paired with a Mac may be able…

  • CVE-2024-55891LowJan 14, 2025
    risk 0.13cvss 3.1epss 0.00

    TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYPO3 versions 13.4.3 ELTS…

  • CVE-2023-5028LowSep 17, 2023
    risk 0.13cvss 2.0epss 0.00

    A vulnerability, which was classified as problematic, has been found in China Unicom TEWA-800G 4.16L.04_CT2015_Yueme. Affected by this issue is some unknown functionality. The manipulation leads to information exposure through debug log file. It is possible to launch the attack…

  • CVE-2023-22447LowMay 10, 2023
    risk 0.13cvss 2.0epss 0.00

    Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2022-33693LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

  • CVE-2021-41808LowJan 18, 2022
    risk 0.13cvss 2.0epss 0.00

    In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.

  • CVE-2021-39900LowOct 4, 2021
    risk 0.13cvss 2.0epss 0.01

    Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

  • CVE-2021-25350LowMar 25, 2021
    risk 0.13cvss 2.0epss 0.00

    Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.

  • CVE-2020-12023LowJun 11, 2020
    risk 0.13cvss 2.0epss 0.01

    Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge Enterprise (IBE) are logged within the…

  • CVE-2015-1343LowApr 22, 2019
    risk 0.13cvss 2.0epss 0.01

    All versions of unity-scope-gdrive logs search terms to syslog.

  • CVE-2023-50301LowOct 1, 2025
    risk 0.12cvss 1.9epss 0.00

    IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2024-12057LowDec 9, 2024
    risk 0.12cvss epss 0.00

    User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by…

  • CVE-2022-25830LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25829LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log