VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 60 of 60
  • CVE-2021-21361MedMar 9, 2021
    risk 0.00cvss 5.3epss 0.01

    The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious…

  • CVE-2020-8566MedDec 7, 2020
    risk 0.00cvss 4.7epss 0.01

    In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, <…

  • CVE-2020-8563MedDec 7, 2020
    risk 0.00cvss 4.7epss 0.01

    In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.

  • CVE-2020-10752HigJun 12, 2020
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked…

  • CVE-2020-13881HigJun 6, 2020
    risk 0.00cvss 7.5epss 0.02

    In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.

  • CVE-2020-11932LowMay 13, 2020
    risk 0.00cvss 2.3epss 0.01

    It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.

  • CVE-2019-10165LowJul 30, 2019
    risk 0.00cvss 2.3epss 0.00

    OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

  • CVE-2019-9734HigApr 24, 2019
    risk 0.00cvss 7.5epss 0.02

    Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances.

  • CVE-2018-1000123CriMar 13, 2018
    risk 0.00cvss 9.8epss 0.01

    Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other sensitive data leakage. This attack…

  • CVE-2018-1000060CriFeb 9, 2018
    risk 0.00cvss 9.8epss 0.02

    Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data (e.g. passwords) may be logged in clear-text. This attack…

  • CVE-2014-1948Feb 14, 2014
    risk 0.00cvss epss 0.00

    OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive…

  • CVE-2013-6384Nov 23, 2013
    risk 0.00cvss epss 0.00

    (1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log…

  • CVE-2011-2204Jun 29, 2011
    risk 0.00cvss epss 0.01

    Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log…

  • CVE-2011-1943Jun 14, 2011
    risk 0.00cvss epss 0.00

    The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file.

  • CVE-2007-0902Feb 13, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the "Show debugging information" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2001-1556Dec 31, 2001
    risk 0.00cvss epss 0.04

    The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail,…