CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Emc 2Recoverpoint Recoverpoint For Virtual MachinesNov 21, 2024 May 29, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious...Show more |
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs. |
2Canonical Openstack2Oslo.middleware Ubuntu LinuxNov 21, 2024 May 8, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users cou...Show more |
1Wpsecurityauditlog 1Wp Security Audit Log Jun 17, 2026 Apr 4, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for...Show more |
1Ibm 1Qradar Security Information And Event Manager Nov 21, 2024 Apr 4, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914. |
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information. |
1Vmware 1Pivotal Software Mysql Nov 21, 2024 Mar 29, 2018 N/A· v4 10.0 CRITICAL· v3 5.0 MEDIUM· v2 MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside th...Show more |
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration. |
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration. |
1Ionicframework 1Ios Keychain Nov 21, 2024 Mar 13, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login,...Show more |
1Django Anymail Project 1Django Anymail Nov 21, 2024 Mar 13, 2018 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email track...Show more |
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, th...Show more |
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page. |
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables. |
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles. |
2Fedoraproject Opensuse2Fedora ZypperNov 21, 2024 Mar 1, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used. |
1Trendmicro 1Interscan Messaging Security Virtual Appliance Nov 21, 2024 Feb 16, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be u...Show more |
1Sap 1Hana Extended Application Services Nov 21, 2024 Feb 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication. |
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data...Show more |
1Ovirt 1Ovirt Hosted Engine Setup Nov 21, 2024 Jan 24, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file. |