← Back
CWE-532

1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,164)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Ssh Agent
Nov 21, 2024
Aug 1, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build lo...Show more
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.Show less
2Openstack
Redhat
2Heat
Openstack
Nov 21, 2024
Jul 27, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this fl...Show more
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.Show less
2Ovirt
Redhat
2Ovirt
Virtualization
Nov 21, 2024
Jul 27, 2018
N/A· v4
6.6 MEDIUM· v3
3.5 LOW· v2
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents...Show more
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.Show less
1Vmware
1Horizon View Agents
Jun 17, 2026
Jul 25, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is...Show more
VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this issue may allow low privileged users access to the credentials specified during the Horizon View Agent installation.Show less
1Zohocorp
1Manageengine Desktop Central
Nov 21, 2024
Jul 16, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Us...Show more
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD account used to send mail), the cleartext password of recovery_password of Android devices, the cleartext password of account "set", the location of devices enrolled in the platform (with UUID and information related to the name of the person at the location), critical information about all enrolled devices such as Serial Number, UUID, Model, Name, and auth_session_token (usable to spoof a terminal identity on the platform), etc.Show less
1Zohocorp
1Manageengine Desktop Central
Nov 21, 2024
Jul 16, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such...Show more
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.Show less
1Juniper
1Contrail Service Orchestration
Nov 21, 2024
Jul 11, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
1Sap
1Dynamic Authorization Management
Nov 21, 2024
Jul 10, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.
1Moodle
1Moodle
Nov 21, 2024
Jul 10, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.
1Ibm
1Websphere Mq Managed File Transfer
Nov 21, 2024
Jul 6, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.
3Canonical
DebianRedhat
6Ansible Engine
CloudformsDebian Linux+3 more
Nov 21, 2024
Jul 3, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does...Show more
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.Show less
2Ovirt
Redhat
2Enterprise Virtualization Manager
Ovirt
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in c...Show more
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.Show less
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.
1Njtech
1Greencms
Nov 21, 2024
Jun 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt Ansible Roles
Nov 21, 2024
Jun 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provis...Show more
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.Show less
1Ovirt
1Ovirt
Nov 21, 2024
Jun 12, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database,...Show more
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.Show less
1Cisco
1Prime Collaboration
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of au...Show more
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific World-Readable file for this authentication data (Cleartext Passwords). An exploit could allow the attacker to gain authentication information for other users. Cisco Bug IDs: CSCvd86602.Show less
1Ibm
3Security Access Manager
Security Access Manager For MobileSecurity Access Manager For Web
Nov 21, 2024
Jun 6, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
1Grunt Gh Pages Project
1Grunt Gh Pages
Nov 21, 2024
May 31, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is output...Show more
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised.Show less