← Back
CWE-532

1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,164)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Cloud Private
Jun 17, 2026
Aug 5, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to the system as another user. IBM X-Force...Show more
IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to the system as another user. IBM X-Force ID: 160512.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
1Jenkins
1Ec2
Jun 17, 2026
Jul 31, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.
1Jenkins
1Maven
Jun 17, 2026
Jul 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.
1Jenkins
1Configuration As Code
Jun 17, 2026
Jul 31, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
1Jenkins
1Configuration As Code
Jun 17, 2026
Jul 31, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.
1Redhat
1Openshift Container Platform
Jun 17, 2026
Jul 30, 2019
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens fr...Show more
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.Show less
1Apache
1Storm
Jun 17, 2026
Jul 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file sy...Show more
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.Show less
1Octopus
1Octopus Deploy
Jun 17, 2026
Jul 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the...Show more
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.3. The fix was back-ported to LTS 2019.6.5 as well as LTS 2019.3.7.Show less
1Pivotal Software
1Pivotal Container Service
Jun 17, 2026
Jul 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user...Show more
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be able to retrieve non-sensitive information.Show less
1Tronlink
1Wallet
Jun 17, 2026
Jul 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be r...Show more
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the device has the capability to read data logged by other applications.Show less
1Docker
1Docker
Jun 17, 2026
Jul 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docke...Show more
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.Show less
2Ovirt
Redhat
2Ovirt
Virtualization Manager
Jun 17, 2026
Jul 11, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks...Show more
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's tok...Show more
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.Show less
1Ibm
1Robotic Process Automation With Automation Anywhere
Jun 17, 2026
Jul 1, 2019
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765.
1Ibm
1Robotic Process Automation With Automation Anywhere
Jun 17, 2026
Jul 1, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759.
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jun 27, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerabili...Show more
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software. An attacker could exploit this vulnerability by connecting to the web-based management interface of an affected device and requesting specific URLs. A successful exploit could allow the attacker to download log files and diagnostic information from the affected device.Show less