← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
1Vcenter Server
Jun 17, 2026
Sep 18, 2019
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed t...Show more
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).Show less
1Dell
2Rsa Identity Governance And Lifecycle
Rsa Via Lifecycle And Governance
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability. The Office 365 user password may get logged in a plain te...Show more
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability. The Office 365 user password may get logged in a plain text format in the Office 365 connector debug log file. An authenticated malicious local user with access to the debug logs may obtain the exposed password to use in further attacks.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
Sep 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug repo...Show more
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged into the system even if the log was redacted for privacy. This has been fixed (in 5.5.4 and 6.0.1) so that usernames are tagged properly in the logs and are hashed out when the logs are redacted.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT cr...Show more
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.Show less
2F5
Redhat
2Container Ingress Service
Openshift
Jun 17, 2026
Sep 4, 2019
N/A· v4
4.4 MEDIUM· v3
1.9 LOW· v2
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphr...Show more
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by an AS3 Declaration.Show less
2Kubernetes
Redhat
2Kubernetes
Openshift Container Platform
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) pri...Show more
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.Show less
1Gallagher
1Command Centre
Jun 17, 2026
Aug 28, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password fo...Show more
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password for this service are logged in cleartext to the Command_centre.log file.Show less
1Octopus
2Server
Tentacle
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request p...Show more
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 5.0.1. The fix was back-ported to 4.0.7.Show less
1Octopus
1Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request...Show more
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.7. The fix was back-ported to LTS 2019.6.7 as well as LTS 2019.3.8.Show less
1Belwith Keeler
1Hickory Smart
Jun 17, 2026
Aug 22, 2019
N/A· v4
4.3 MEDIUM· v3
2.1 LOW· v2
An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to th...Show more
An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile application are logged in a debug log on the Android device at HickorySmartLog/Logs/SRDeviceLog.txt. This information was found stored in the Android device's default USB or SDcard storage paths and is accessible without rooting the device. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.Show less
1Osisoft
1Pi Web Api
Jun 17, 2026
Aug 15, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.
1Swann
1Swwhd Intcam Hd Firmware
Nov 21, 2024
Aug 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31.
1Cisco
2Enterprise Network Function Virtualization Infrastructure
Enterprise Nfv Infrastructure Software
Aug 24, 2026
Aug 8, 2019
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerabili...Show more
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to the improper input validation of tar packages uploaded through the Web Portal to the Image Repository. An attacker could exploit this vulnerability by uploading a crafted tar package and viewing the log entries that are generated. A successful exploit could allow the attacker to read arbitrary files on the underlying OS.Show less
1Cisco
2Enterprise Network Function Virtualization Infrastructure
Enterprise Nfv Infrastructure Software
Aug 24, 2026
Aug 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging th...Show more
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced to modify the default password when logging in to the web portal for the first time. Subsequent password changes are not logged and other accounts are not affected. An attacker could exploit this vulnerability by viewing the admin clear text password and using it to access the affected system. The attacker would need a valid user account to exploit this vulnerability.Show less
1Jenkins
1Mask Passwords
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.
1Jenkins
1Configuration As Code
Jun 17, 2026
Aug 7, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.
1Ibm
1Cloud Private
Jun 17, 2026
Aug 5, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to the system as another user. IBM X-Force...Show more
IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to the system as another user. IBM X-Force ID: 160512.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).