← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Desktop Central
Nov 21, 2024
Jul 16, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Us...Show more
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD account used to send mail), the cleartext password of recovery_password of Android devices, the cleartext password of account "set", the location of devices enrolled in the platform (with UUID and information related to the name of the person at the location), critical information about all enrolled devices such as Serial Number, UUID, Model, Name, and auth_session_token (usable to spoof a terminal identity on the platform), etc.Show less
1Zohocorp
1Manageengine Desktop Central
Nov 21, 2024
Jul 16, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such...Show more
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.Show less
1Juniper
1Contrail Service Orchestration
Nov 21, 2024
Jul 11, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
1Sap
1Dynamic Authorization Management
Nov 21, 2024
Jul 10, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.
1Moodle
1Moodle
Nov 21, 2024
Jul 10, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.
1Ibm
1Websphere Mq Managed File Transfer
Nov 21, 2024
Jul 6, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.
3Canonical
DebianRedhat
6Ansible Engine
CloudformsDebian Linux+3 more
Nov 21, 2024
Jul 3, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does...Show more
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.Show less
2Ovirt
Redhat
2Enterprise Virtualization Manager
Ovirt
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in c...Show more
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.Show less
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.
1Njtech
1Greencms
Nov 21, 2024
Jun 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt Ansible Roles
Nov 21, 2024
Jun 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provis...Show more
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.Show less
1Ovirt
1Ovirt
Nov 21, 2024
Jun 12, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database,...Show more
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.Show less
1Cisco
1Prime Collaboration
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of au...Show more
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific World-Readable file for this authentication data (Cleartext Passwords). An exploit could allow the attacker to gain authentication information for other users. Cisco Bug IDs: CSCvd86602.Show less
1Ibm
3Security Access Manager
Security Access Manager For MobileSecurity Access Manager For Web
Nov 21, 2024
Jun 6, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
1Grunt Gh Pages Project
1Grunt Gh Pages
Nov 21, 2024
May 31, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is output...Show more
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised.Show less
1Emc
2Recoverpoint
Recoverpoint For Virtual Machines
Nov 21, 2024
May 29, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious...Show more
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in further attacks.Show less
1Octopus
1Octopus Server
Nov 21, 2024
May 21, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.
2Canonical
Openstack
2Oslo.middleware
Ubuntu Linux
Nov 21, 2024
May 8, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users cou...Show more
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).Show less
1Wpsecurityauditlog
1Wp Security Audit Log
Jun 17, 2026
Apr 4, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for...Show more
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.Show less