← Back
CWE-532

1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,164)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Emc
2Recoverpoint
Recoverpoint For Virtual Machines
Nov 21, 2024
May 29, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious...Show more
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in further attacks.Show less
1Octopus
1Octopus Server
Nov 21, 2024
May 21, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.
2Canonical
Openstack
2Oslo.middleware
Ubuntu Linux
Nov 21, 2024
May 8, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users cou...Show more
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).Show less
1Wpsecurityauditlog
1Wp Security Audit Log
Jun 17, 2026
Apr 4, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for...Show more
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.Show less
1Ibm
1Qradar Security Information And Event Manager
Nov 21, 2024
Apr 4, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.
1Elastic
1Logstash
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
1Vmware
1Pivotal Software Mysql
Nov 21, 2024
Mar 29, 2018
N/A· v4
10.0 CRITICAL· v3
5.0 MEDIUM· v2
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside th...Show more
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.Show less
1Netiq
1Identity Manager
Nov 21, 2024
Mar 26, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
1Netiq
1Identity Manager
Nov 21, 2024
Mar 26, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
1Ionicframework
1Ios Keychain
Nov 21, 2024
Mar 13, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login,...Show more
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other sensitive data leakage. This attack appear to be exploitable via Attacker must have access to victim's iOS logs. This vulnerability appears to have been fixed in after commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf.Show less
1Django Anymail Project
1Django Anymail
Nov 21, 2024
Mar 13, 2018
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email track...Show more
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.Show less
1Giribaz
1File Manager
Jun 17, 2026
Mar 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, th...Show more
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and a simple dork will find affected sites.Show less
1Ithemes
1Security
Jun 17, 2026
Mar 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
1Netiq
1Identity Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
1Netiq
1Identity Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
2Fedoraproject
Opensuse
2Fedora
Zypper
Nov 21, 2024
Mar 1, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
1Trendmicro
1Interscan Messaging Security Virtual Appliance
Nov 21, 2024
Feb 16, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be u...Show more
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on vulnerable installations.Show less
1Sap
1Hana Extended Application Services
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.
1Sensu
1Sensu Core
Nov 21, 2024
Feb 9, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data...Show more
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data (e.g. passwords) may be logged in clear-text. This attack appear to be exploitable via victims with configuration matching a specific pattern will observe sensitive data outputted in their service log files. This vulnerability appears to have been fixed in 1.2.1 and later, after commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b.Show less
1Ovirt
1Ovirt Hosted Engine Setup
Nov 21, 2024
Jan 24, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.