CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build lo...Show more |
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this fl...Show more |
2Ovirt Redhat2Ovirt VirtualizationNov 21, 2024 Jul 27, 2018 N/A· v4 6.6 MEDIUM· v3 3.5 LOW· v2 ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents...Show more |
VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is...Show more |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Jul 16, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Us...Show more |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Jul 16, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such...Show more |
1Juniper 1Contrail Service Orchestration Nov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability. |
1Sap 1Dynamic Authorization Management Nov 21, 2024 Jul 10, 2018 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs. |
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester. |
1Ibm 1Websphere Mq Managed File Transfer Nov 21, 2024 Jul 6, 2018 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042. |
3Canonical DebianRedhat6Ansible Engine CloudformsDebian Linux+3 moreNov 21, 2024 Jul 3, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does...Show more |
2Ovirt Redhat2Enterprise Virtualization Manager OvirtNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in c...Show more |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Jun 22, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains. |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Jun 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files. |
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log. |
2Ovirt Redhat2Enterprise Virtualization Ovirt Ansible RolesNov 21, 2024 Jun 20, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provis...Show more |
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database,...Show more |
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of au...Show more |
1Ibm 3Security Access Manager Security Access Manager For MobileSecurity Access Manager For WebNov 21, 2024 Jun 6, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617. |
1Grunt Gh Pages Project 1Grunt Gh Pages Nov 21, 2024 May 31, 2018 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is output...Show more |