VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 6 of 60
  • CVE-2018-19786HigDec 5, 2018
    risk 0.53cvss 8.1epss 0.01

    HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.

  • CVE-2018-3827HigSep 19, 2018
    risk 0.53cvss 8.1epss 0.01

    A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.

  • CVE-2018-12604HigJun 20, 2018
    risk 0.53cvss 7.5epss 0.13

    GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

  • CVE-2025-23374HigJan 30, 2025
    risk 0.52cvss 8.0epss 0.00

    Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2023-46675HigDec 13, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug level logging is enabled in Kibana. Elastic has released Kibana 8.11.2 which resolves this issue. The messages recorded in the log…

  • CVE-2023-46671HigDec 13, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana 8.11.1 which resolves this issue. The error message recorded in the log may contain account credentials for the kibana_system…

  • CVE-2023-28441HigMar 24, 2023
    risk 0.52cvss 8.0epss 0.00

    smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affected log file, and ensure one logs in…

  • CVE-2022-31098CriJun 27, 2022
    risk 0.52cvss 9.0epss 0.01

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka…

  • CVE-2026-40619HigJun 2, 2026
    risk 0.51cvss 7.8epss 0.00

    A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is…

  • CVE-2026-28261HigApr 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this…

  • CVE-2025-11547HigFeb 10, 2026
    risk 0.51cvss 7.8epss 0.00

    AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.

  • CVE-2025-34188HigSep 19, 2025
    risk 0.51cvss 7.8epss 0.00

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local logging mechanism. Authentication session tokens, including PHPSESSID, XSRF-TOKEN, and…

  • CVE-2024-12569HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions.

  • CVE-2024-25959HigMar 28, 2024
    risk 0.51cvss 7.9epss 0.00

    Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.

  • CVE-2022-0010HigMay 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information,…

  • CVE-2023-22573HigFeb 1, 2023
    risk 0.51cvss 7.9epss 0.00

    Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure.

  • CVE-2023-22572HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeover.

  • CVE-2021-36289HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.

  • CVE-2021-21561HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files.

  • CVE-2021-36340HigNov 20, 2021
    risk 0.51cvss 7.8epss 0.00

    Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.