CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Suse 1Rancher Backup And Restore Operator Jun 17, 2026 Mar 4, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs. |
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file. |
In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privi...Show more |
The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is no...Show more |
1Hitachi 2Configuration Manager Ops Center Api Configuration ManagerJun 17, 2026 Feb 25, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi...Show more |
1Hitachi 3Configuration Manager Device ManagerOps Center Api Configuration ManagerJun 17, 2026 Feb 25, 2026 N/A· v4 5.2 MEDIUM· v3 N/A· v2 Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration M...Show more |
Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via...Show more |
Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS. |
Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS. |
Tanium addressed an insertion of sensitive information into log file vulnerability in Trends. |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Feb 18, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC...Show more |
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the RSA `acces...Show more |
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the `integrat...Show more |
The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to enumerate a user's installed apps. |
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information. |
The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could en...Show more |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJun 17, 2026 Feb 10, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. |
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user. |
1Rageagainstthepixel 1Unity Cli Jun 17, 2026 Feb 9, 2026 5.9 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Comma...Show more |
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly to console output without masking or redaction. |