← Back
CWE-117

114 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Output Neutralization for Logs

The product does not neutralize or incorrectly neutralizes output that is written to logs.

JSON object

Loading...

CVEs (114)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Airavata Django Portal
Jun 17, 2026
Dec 9, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch bef...Show more
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1] https://github.com/apache/airavata-django-portal/commit/3c5d8c72bfc3eb0af8693a655a5d60f9273f8170Show less
1Apache
1Superset
Jun 17, 2026
Nov 17, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
3Netapp
OracleVmware
8Active Iq Unified Manager
Communications Cloud Native Core ConsoleCommunications Cloud Native Core Service Communication Proxy+5 more
Jun 17, 2026
Oct 28, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
1Mongodb
1Mongodb
Jun 17, 2026
Jul 23, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server...Show more
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.Show less
1Ansible Collections Project
1Community.crypto
Jun 17, 2026
Oct 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality
1Br Automation
3Gatemanager 4260 Firmware
Gatemanager 8250 FirmwareGatemanager 9250 Firmware
Jun 17, 2026
Oct 15, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The information disclosure vulnerability present in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to generate fake audit log messages.
2Debian
Redhat
2Ansible Engine
Debian Linux
Jun 17, 2026
Sep 11, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to rea...Show more
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.Show less
1Jhipster
1Generator Jhipster Kotlin
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This...Show more
In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable. This issue has been fixed in version 1.7.0.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Jan 7, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret mater...Show more
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.Show less
3Debian
OpensuseRedhat
8Ansible
Ansible TowerBackports Sle+5 more
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results e...Show more
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discove...Show more
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.Show less
1Redhat
2Ansible Engine
Ansible Tower
Jun 17, 2026
Oct 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cau...Show more
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.Show less
3Debian
OpensuseRedhat
5Ansible Engine
Backports SleDebian Linux+2 more
Jun 17, 2026
Oct 8, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that...Show more
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.Show less
1Intel
1Lldptool
Nov 21, 2024
Aug 21, 2018
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the...Show more
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.Show less