← Back
CWE-532

1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,164)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hashicorp
1Vault
Nov 21, 2024
Dec 5, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
1Drobo
15n2 Firmware
Nov 21, 2024
Dec 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter.
1Redhat
1Ansible Engine
Nov 21, 2024
Nov 29, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator pri...Show more
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.Show less
1Lenovo
1System Management Module Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.
1Ibm
1Robotic Process Automation With Automation Anywhere
Nov 21, 2024
Nov 2, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.
1Circontrol
1Circarlife Firmware
Nov 21, 2024
Nov 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
1Ibm
1Spectrum Protect Server
Nov 21, 2024
Nov 2, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.
1Citrix
2Netscaler Sd Wan
Sd Wan
Nov 21, 2024
Oct 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
1Pivotal Software
1Pivotal Container Service
Nov 21, 2024
Oct 5, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obt...Show more
Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obtain IaaS credentials and perform actions using these credentials.Show less
1Pivotal Software
1Cloud Foundry Log Cache
Nov 21, 2024
Oct 5, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache VM can read this secret, gaining all privi...Show more
Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache VM can read this secret, gaining all privileges held by the Log Cache UAA client. In the worst case, if this client is an admin, the attacker would gain complete control over the Foundation.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Oct 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
1Gitlab
1Gitlab
Nov 21, 2024
Oct 3, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message.
1Ibm
1Spectrum Protect Plus
Nov 21, 2024
Sep 26, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log fil...Show more
IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log file. IBM X-Force ID: 148622.Show less
1Elastic
1Elastic Cloud Enterprise
Nov 21, 2024
Sep 19, 2018
N/A· v4
7.5 HIGH· v3
3.5 LOW· v2
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sen...Show more
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers being leaked to the allocator logs. An attacker with access to the logging cluster may obtain leaked credentials and perform authenticated actions using these credentials.Show less
1Elastic
1Azure Repository
Nov 21, 2024
Sep 19, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadver...Show more
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.Show less
1Pivotal
1Cloud Foundry Container Runtime
Nov 21, 2024
Sep 17, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentia...Show more
Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate privileges.Show less
1Pivotal Software
1Pivotal Cloud Cache
Nov 21, 2024
Sep 17, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password.
1Orbic
1Wonder Rc555l Firmware
Jun 17, 2026
Aug 29, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Andro...Show more
An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Android log on the SD card. The system-wide Android logs are not directly available to third-party apps since they tend to contain sensitive data. Third-party apps can read from the log but only the log messages that the app itself has written. Certain apps can leak data to the Android log due to not sanitizing log messages, which is in an insecure programming practice. Pre-installed system apps and apps that are signed with the framework key can read from the system-wide Android log. We found a pre-installed app on the Orbic Wonder that when started via an Intent will write the Android log to the SD card, also known as external storage, via com.ckt.mmitest.MmiMainActivity. Any app that requests the READ_EXTERNAL_STORAGE permission can read from the SD card. Therefore, a local app on the device can quickly start a specific component in the pre-installed system app to have the Android log written to the SD card. Therefore, any app co-located on the device with the READ_EXTERNAL_STORAGE permission can obtain the data contained within the Android log and continually monitor it and mine the log for relevant data. In addition, the default messaging app (com.android.mms) writes the body of sent and received text messages to the Android log, as well as the recipient phone number for sent text messages and the sending phone number for received text messages. In addition, any call data contains phone numbers for sent and received calls.Show less
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Aug 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.
1Linux
1Linux Kernel
Jun 17, 2026
Aug 10, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree: " lines in a debugfs file.