VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 57 of 60
  • CVE-2022-25828LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25827LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25826LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25823LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.

  • CVE-2016-2943LowNov 30, 2016
    risk 0.12cvss 1.9epss 0.00

    IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.

  • CVE-2025-54781LowAug 2, 2025
    risk 0.11cvss 2.8epss 0.00

    Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau in version 1.0.0, the himmelblaud_tasks service leaks an Intune service access token to the system journal. This short-lived token can be used to detect the…

  • CVE-2023-45809LowOct 19, 2023
    risk 0.11cvss 2.7epss 0.00

    Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for the Wagtail admin can make a direct URL request to the admin view that handles bulk actions on user accounts. While authentication rules prevent the user from…

  • CVE-2023-22733LowJan 17, 2023
    risk 0.11cvss 2.7epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized logging store may have access to other users…

  • CVE-2025-55285LowAug 15, 2025
    risk 0.10cvss 2.6epss 0.00

    @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly redacted. If ${{…

  • CVE-2021-22133LowFeb 10, 2021
    risk 0.09cvss 2.4epss 0.01

    The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an…

  • CVE-2024-34715LowMay 29, 2024
    risk 0.08cvss 2.3epss 0.00

    Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL database for persistent storage of application data. If the password used by the webserver for this database connection includes special characters such as `@`…

  • CVE-2024-51753LowNov 5, 2024
    risk 0.07cvss epss 0.00

    The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched…

  • CVE-2021-22143LowNov 22, 2023
    risk 0.07cvss 2.1epss 0.01

    The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is…

  • CVE-2024-35196LowMay 31, 2024
    risk 0.06cvss 2.0epss 0.01

    Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly records the incoming request body in logs. This request data can contain sensitive information, including the deprecated Slack verification token. With this…

  • CVE-2025-32382LowApr 10, 2025
    risk 0.05cvss epss 0.00

    Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing password to private key or vice versa), Metabase would not always purge older Snowflake connection…

  • CVE-2026-55102Aug 13, 2026
    risk 0.00cvss epss

    ## Summary Vault token and secret values are exposed in thrown errors when using `hashi-vault-js`. ## Details Every API method in `Vault.js` executes `throw parseAxiosError(err)`, which returns the raw `AxiosError` untouched. That error carries the full Axios configuration,…

  • CVE-2026-65311MedJul 31, 2026
    risk 0.00cvss 5.3epss 0.00

    The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service…

  • CVE-2026-44105MedJul 30, 2026
    risk 0.00cvss 6.6epss 0.00

    The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.

  • CVE-2026-59326LowJul 30, 2026
    risk 0.00cvss 3.3epss 0.00

    The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently…

  • CVE-2026-1918MedJul 28, 2026
    risk 0.00cvss 4.9epss 0.00

    IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 stores potentially sensitive information in log files…