CWE-117
102 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Output Neutralization for Logs
The product does not neutralize or incorrectly neutralizes output that is written to logs.
CVEs (102)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files that, when a vulnerable terminal application read...Show more |
A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information. List o...Show more |
1Schneider Electric 4Clearscada Ecostruxure Geo Scada Expert 2019Ecostruxure Geo Scada Expert 2020+1 moreJun 17, 2026 Feb 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affec...Show more |
A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the file resolverapi/endpoints.py. The manipulation leads to improper output neutralization for logs. The i...Show more |
1Cognex 13d A1000 Dimensioning System Firmware Jun 17, 2026 Sep 6, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Output Neutralization for Logs, which allows an attacker to create false logs that show the password a...Show more |
1Apache 2Sling Api Sling Commons LogJun 17, 2026 Jun 22, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files. |
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator. |
1Yokogawa 5Centum Cs 3000 Entry Firmware Centum Cs 3000 FirmwareCentum Vp Entry Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, fro...Show more |
1Apache 1Airavata Django Portal Jun 17, 2026 Dec 9, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch bef...Show more |
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. |
3Netapp OracleVmware8Active Iq Unified Manager Communications Cloud Native Core ConsoleCommunications Cloud Native Core Service Communication Proxy+5 moreJun 17, 2026 Oct 28, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. |
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server...Show more |
1Ansible Collections Project 1Community.crypto Jun 17, 2026 Oct 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality |
1Br Automation 3Gatemanager 4260 Firmware Gatemanager 8250 FirmwareGatemanager 9250 FirmwareJun 17, 2026 Oct 15, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The information disclosure vulnerability present in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to generate fake audit log messages. |
2Debian Redhat2Ansible Engine Debian LinuxJun 17, 2026 Sep 11, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to rea...Show more |
1Jhipster 1Generator Jhipster Kotlin Jun 17, 2026 Jun 25, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jan 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret mater...Show more |
3Debian OpensuseRedhat8Ansible Ansible TowerBackports Sle+5 moreJun 17, 2026 Jan 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results e...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Nov 25, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discove...Show more |
1Redhat 2Ansible Engine Ansible TowerJun 17, 2026 Oct 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cau...Show more |