CWE-532
1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,220)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Jboss Enterprise Application Platform Single Sign OnJun 17, 2026 Jan 23, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI...Show more |
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR...Show more |
In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts are customized during installation or upgrade of PI Vision. The update fixes a pre...Show more |
1Pivotal Software 1Operations Manager Jun 17, 2026 Jan 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jan 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret mater...Show more |
3Debian OpensuseRedhat8Ansible Ansible TowerBackports Sle+5 moreJun 17, 2026 Jan 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results e...Show more |
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information. |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Dec 23, 2019 N/A· v4 4.9 MEDIUM· v3 3.5 LOW· v2 On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session policy is attached to the virtual server...Show more |
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/local/cwpsrv/logs/acce...Show more |
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp directory, and the victim's token value from /usr/local/cwpsrv/logs/access_l...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Dec 15, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration |
1Puppet 1Continuous Delivery Jun 17, 2026 Dec 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details pane in the PE console. These issues have...Show more |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationJun 17, 2026 Dec 6, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user crede...Show more |
2Fedoraproject Freeipa2Fedora FreeipaJun 17, 2026 Nov 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user...Show more |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationJun 17, 2026 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. |
1Redhat 1Openshift Container Platform Jun 17, 2026 Nov 25, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discove...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Nov 21, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Nov 15, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that...Show more |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moodle before 2.2.2 has users' private files included in course backups |
1Mcafee 1Advanced Threat Defense Jun 17, 2026 Nov 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incor...Show more |