← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Broadcom
1Brocade Sannav
Jun 17, 2026
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
1Broadcom
1Brocade Sannav
Jun 17, 2026
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive...Show more
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.Show less
1Monkey Project
1Monkey
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
1Apache
1Impala
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
4.6 MEDIUM· v2
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query IDs are unique and random, but have not been documented or consistently treated as sensitive secrets. Therefore they may be exposed in logs or interfaces. They were also not generated with a cryptographically secure random number generator, so are vulnerable to random number generator attacks that predict future IDs based on past IDs. Impala deployments with Apache Sentry or Apache Ranger authorization enabled may be vulnerable to privilege escalation if an authenticated attacker is able to hijack a session or query from another authenticated user with privileges not assigned to the attacker. Impala deployments with audit logging enabled may be vulnerable to incorrect audit logging as a user could undertake actions that were logged under the name of a different authenticated user. Constructing an attack requires a high degree of technical sophistication and access to the Impala system as an authenticated user.Show less
1Terra Master
1Fs 210 Firmware
Jun 17, 2026
Oct 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.
2Cloudfoundry
Pivotal Software
2Cf Deployment
Cloud Foundry Smb Volume
Jun 17, 2026
Oct 23, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have be...Show more
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.Show less
1Rapidgator
1Rapidgator
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Darkhorse
1Dark Horse Comics
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat.
1Powerschool
1Powerschool Mobile
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Seesaw
1Parent And Family
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Orbitz
1Orbitz
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Doordash
1Doordash
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Redhat
2Ansible Engine
Ansible Tower
Jun 17, 2026
Oct 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cau...Show more
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.Show less
1Ibm
1Filenet Content Manager
Jun 17, 2026
Oct 14, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine. IBM X-Force ID: 166798.
1Sap
1Landscape Management
Jun 17, 2026
Oct 8, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
3Debian
OpensuseRedhat
5Ansible Engine
Backports SleDebian Linux+2 more
Jun 17, 2026
Oct 8, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that...Show more
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.Show less
2Netapp
Redhat
7Active Iq Unified Manager
Jboss Data GridJboss Enterprise Application Platform+4 more
Jun 17, 2026
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
4.3 MEDIUM· v2
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
1Enterprisedt
1Completeftp Server
Jun 17, 2026
Oct 2, 2019
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interactio...Show more
In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-68016944Show less
1F5
2Big Ip Access Policy Manager
Big Ip Access Policy Manager Client
Jun 17, 2026
Sep 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0...Show more
BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5. In BIG-IP APM 13.1.0 and later, the APM Clients components can be updated independently from BIG-IP software. Client version 7.1.8 (7180.2019.508.705) and later has the fix.Show less