CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported. |
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter. |
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator pri...Show more |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails. |
1Ibm 1Robotic Process Automation With Automation Anywhere Nov 21, 2024 Nov 2, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707. |
1Circontrol 1Circarlife Firmware Nov 21, 2024 Nov 2, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication. |
IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873. |
1Citrix 2Netscaler Sd Wan Sd WanNov 21, 2024 Oct 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
1Pivotal Software 1Pivotal Container Service Nov 21, 2024 Oct 5, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obt...Show more |
1Pivotal Software 1Cloud Foundry Log Cache Nov 21, 2024 Oct 5, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache VM can read this secret, gaining all privi...Show more |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Oct 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid |
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message. |
IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log fil...Show more |
1Elastic 1Elastic Cloud Enterprise Nov 21, 2024 Sep 19, 2018 N/A· v4 7.5 HIGH· v3 3.5 LOW· v2 Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sen...Show more |
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadver...Show more |
1Pivotal 1Cloud Foundry Container Runtime Nov 21, 2024 Sep 17, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentia...Show more |
1Pivotal Software 1Pivotal Cloud Cache Nov 21, 2024 Sep 17, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password. |
An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Andro...Show more |
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. |
The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree: " lines in a debugfs file. |