VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,257)

page 60 of 63
  • CVE-2025-13611LowNov 26, 2025
    risk 0.13cvss 2.0epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

  • CVE-2025-43423LowNov 4, 2025
    risk 0.13cvss 2.0epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical access to an unlocked device paired with a Mac may be able…

  • CVE-2024-55891LowJan 14, 2025
    risk 0.13cvss 3.1epss 0.00

    TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYPO3 versions 13.4.3 ELTS…

  • CVE-2023-5028LowSep 17, 2023
    risk 0.13cvss 2.0epss 0.00

    A vulnerability, which was classified as problematic, has been found in China Unicom TEWA-800G 4.16L.04_CT2015_Yueme. Affected by this issue is some unknown functionality. The manipulation leads to information exposure through debug log file. It is possible to launch the attack…

  • CVE-2023-22447LowMay 10, 2023
    risk 0.13cvss 2.0epss 0.00

    Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2022-33693LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

  • CVE-2021-41808LowJan 18, 2022
    risk 0.13cvss 2.0epss 0.00

    In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.

  • CVE-2021-39900LowOct 4, 2021
    risk 0.13cvss 2.0epss 0.01

    Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

  • CVE-2021-25350LowMar 25, 2021
    risk 0.13cvss 2.0epss 0.00

    Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.

  • CVE-2020-12023LowJun 11, 2020
    risk 0.13cvss 2.0epss 0.01

    Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge Enterprise (IBE) are logged within the…

  • CVE-2015-1343LowApr 22, 2019
    risk 0.13cvss 2.0epss 0.01

    All versions of unity-scope-gdrive logs search terms to syslog.

  • CVE-2023-50301LowOct 1, 2025
    risk 0.12cvss 1.9epss 0.00

    IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2024-12057LowDec 9, 2024
    risk 0.12cvss —epss 0.00

    User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by…

  • CVE-2022-25830LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25829LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25828LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25827LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25826LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25823LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.

  • CVE-2016-2943LowNov 30, 2016
    risk 0.12cvss 1.9epss 0.00

    IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.