CWE-117
114 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Output Neutralization for Logs
The product does not neutralize or incorrectly neutralizes output that is written to logs.
CVEs (114)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apache 1Airavata Django Portal Jun 17, 2026 Dec 9, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch bef...Show more |
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. |
3Netapp OracleVmware8Active Iq Unified Manager Communications Cloud Native Core ConsoleCommunications Cloud Native Core Service Communication Proxy+5 moreJun 17, 2026 Oct 28, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. |
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server...Show more |
1Ansible Collections Project 1Community.crypto Jun 17, 2026 Oct 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality |
1Br Automation 3Gatemanager 4260 Firmware Gatemanager 8250 FirmwareGatemanager 9250 FirmwareJun 17, 2026 Oct 15, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The information disclosure vulnerability present in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to generate fake audit log messages. |
2Debian Redhat2Ansible Engine Debian LinuxJun 17, 2026 Sep 11, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to rea...Show more |
1Jhipster 1Generator Jhipster Kotlin Jun 17, 2026 Jun 25, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jan 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret mater...Show more |
3Debian OpensuseRedhat8Ansible Ansible TowerBackports Sle+5 moreJun 17, 2026 Jan 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results e...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Nov 25, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discove...Show more |
1Redhat 2Ansible Engine Ansible TowerJun 17, 2026 Oct 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cau...Show more |
3Debian OpensuseRedhat5Ansible Engine Backports SleDebian Linux+2 moreJun 17, 2026 Oct 8, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that...Show more |
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the...Show more |