VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 58 of 60
  • CVE-2026-64800LowJul 23, 2026
    risk 0.00cvss 3.5epss 0.00

    In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

  • CVE-2026-65589MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and…

  • CVE-2026-62211MedJul 17, 2026
    risk 0.00cvss 5.0epss 0.00

    OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature…

  • CVE-2026-46514MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.00

    Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plaintext password and fm_add_extension in Tools/AddExtension.php:172 returned a plaintext secret; Frogman.class.php:2207-2211 used…

  • CVE-2026-15737MedJul 16, 2026
    risk 0.00cvss 5.7epss 0.00

    AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK…

  • CVE-2026-40633HigJul 15, 2026
    risk 0.00cvss 7.8epss 0.00

    Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…

  • CVE-2026-50316MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-22098CriJul 13, 2026
    risk 0.00cvss epss 0.00

    Various sensitive information such as passwords and charging card UIDs are written to log files.

  • CVE-2026-56459MedJul 9, 2026
    risk 0.00cvss 6.2epss 0.00

    HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2026-54652HigJul 8, 2026
    risk 0.00cvss 8.1epss 0.00

    Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request…

  • CVE-2026-46467MedJul 3, 2026
    risk 0.00cvss 5.8epss 0.00

    Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information into log file…

  • CVE-2026-8482MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone…

  • CVE-2026-49088MedJul 1, 2026
    risk 0.00cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may…

  • CVE-2026-12086MedJun 30, 2026
    risk 0.00cvss 6.2epss 0.00

    IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy stores potentially sensitive information in log files that could be read by a local…

  • CVE-2026-13750MedJun 29, 2026
    risk 0.00cvss 5.5epss 0.00

    Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. An attacker could exploit this by obtaining read access to the affected user's local log files, causing…

  • CVE-2026-56457MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.

  • CVE-2025-59868MedJun 27, 2026
    risk 0.00cvss 5.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.

  • CVE-2026-9699MedJun 26, 2026
    risk 0.00cvss 6.8epss 0.00

    Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of…

  • CVE-2026-8330MedJun 25, 2026
    risk 0.00cvss 4.4epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a…

  • CVE-2026-12053HigJun 25, 2026
    risk 0.00cvss 8.6epss 0.01

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.