VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 9 of 60
  • CVE-2024-34559HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.

  • CVE-2024-34527HigMay 6, 2024
    risk 0.49cvss 7.5epss 0.01

    spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged.

  • CVE-2024-33637HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.

  • CVE-2024-32953HigApr 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.

  • CVE-2024-29958HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to…

  • CVE-2024-29957HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.00

    When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.

  • CVE-2024-31259HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5.

  • CVE-2023-44989HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5.

  • CVE-2024-23758HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.log file.

  • CVE-2023-47131HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.

  • CVE-2023-52143HigJan 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37.

  • CVE-2023-6064HigJan 1, 2024
    risk 0.49cvss 7.5epss 0.01

    The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.

  • CVE-2023-47390HigNov 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Headscale through 0.22.3 writes bearer tokens to info-level logs.

  • CVE-2023-5499HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages,…

  • CVE-2023-44155HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-41308HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-35695HigJun 26, 2023
    risk 0.49cvss 7.5epss 0.01

    A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product.

  • CVE-2023-33001HigMay 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

  • CVE-2023-22362HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.01

    SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2,…

  • CVE-2023-25164HigFeb 8, 2023
    risk 0.49cvss 8.6epss 0.01

    Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be added in plaintext to the index.js…