VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,262)

page 63 of 64
  • CVE-2026-54711lowJun 18, 2026
    risk 0.00cvss —epss —

    ### Impact When using .pgpass, database connection information including the username and password will be logged at the debug level. ### Patches Upgrade to version 2.7.1 or greater. ### Workarounds Filter out debug-level logs. ### References This issue was discovered by…

  • CVE-2026-22038HigFeb 4, 2026
    risk 0.00cvss 8.1epss 0.00

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.46, the AutoGPT platform's Stagehand integration blocks log API keys and authentication secrets in…

  • CVE-2025-46329LowApr 29, 2025
    risk 0.00cvss 3.3epss 0.00

    libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the…

  • CVE-2024-28186HigMar 12, 2024
    risk 0.00cvss 7.1epss 0.01

    FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes SMTP server credentials used by an organization in the application to users of the application. This issue arises from the…

  • CVE-2023-50253CriJan 3, 2024
    risk 0.00cvss 9.6epss 0.01

    Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container without the need for additional storage. However, in version 1.0.0-beta.13 and prior, this interface does not verify the permissions of…

  • CVE-2023-5182MedOct 7, 2023
    risk 0.00cvss 5.5epss 0.00

    Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.

  • CVE-2023-34097HigJun 5, 2023
    risk 0.00cvss 7.8epss 0.01

    hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Attackers with access to read system logs will be able to elevate privilege with full access to the…

  • CVE-2023-1786MedApr 26, 2023
    risk 0.00cvss 5.5epss 0.00

    Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

  • CVE-2022-2084MedApr 19, 2023
    risk 0.00cvss 5.5epss 0.00

    Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.

  • CVE-2023-28630MedMar 27, 2023
    risk 0.00cvss 4.2epss 0.00

    GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environment is not correctly configured by administrators to provide access to the relevant PostgreSQL or MySQL backup tools, the credentials for database access may…

  • CVE-2023-22481MedMar 6, 2023
    risk 0.00cvss 4.0epss 0.00

    FreshRSS is a self-hosted RSS feed aggregator. When using the greader API, the provided password is logged in clear in `users/_/log_api.txt` in the case where the authentication fails. The issues occurs in `authorizationToUser()` in `greader.php`. If there is an issue with the…

  • CVE-2022-23506MedJan 3, 2023
    risk 0.00cvss 4.3epss 0.01

    Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does not property mask secrets generated via packer builds. This…

  • CVE-2022-23469LowDec 8, 2022
    risk 0.00cvss 3.5epss 0.01

    Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulnerability in Traefik displaying the Authorization header in its debug logs. In certain cases, if the log level is set to DEBUG, credentials provided using the…

  • CVE-2022-31119LowAug 4, 2022
    risk 0.00cvss 3.1epss 0.01

    Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail would log user passwords to disk in the event of a misconfiguration. Should an attacker gain access to the logs complete access to affected accounts would be…

  • CVE-2022-29869MedApr 28, 2022
    risk 0.00cvss 5.3epss 0.02

    cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.

  • CVE-2022-24875MedApr 21, 2022
    risk 0.00cvss 5.3epss 0.01

    The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and including 1.1.1 the `org.conroller.js` code would erroneously log user secrets. This has been resolved in commit `46d98f2b` and should be available in subsequent…

  • CVE-2014-1948Feb 14, 2014
    risk 0.00cvss —epss 0.00

    OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive…

  • CVE-2013-6384Nov 23, 2013
    risk 0.00cvss —epss 0.00

    (1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log…

  • CVE-2011-2204Jun 29, 2011
    risk 0.00cvss —epss 0.01

    Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log…

  • CVE-2011-1943Jun 14, 2011
    risk 0.00cvss —epss 0.00

    The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file.