← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Qradar Security Information And Event Manager
Nov 21, 2024
Apr 4, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.
1Elastic
1Logstash
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
1Vmware
1Pivotal Software Mysql
Nov 21, 2024
Mar 29, 2018
N/A· v4
10.0 CRITICAL· v3
5.0 MEDIUM· v2
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside th...Show more
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.Show less
1Netiq
1Identity Manager
Nov 21, 2024
Mar 26, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
1Netiq
1Identity Manager
Nov 21, 2024
Mar 26, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
1Ionicframework
1Ios Keychain
Nov 21, 2024
Mar 13, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login,...Show more
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other sensitive data leakage. This attack appear to be exploitable via Attacker must have access to victim's iOS logs. This vulnerability appears to have been fixed in after commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf.Show less
1Django Anymail Project
1Django Anymail
Nov 21, 2024
Mar 13, 2018
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email track...Show more
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.Show less
1Giribaz
1File Manager
Jun 17, 2026
Mar 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, th...Show more
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and a simple dork will find affected sites.Show less
1Ithemes
1Security
Jun 17, 2026
Mar 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
1Netiq
1Identity Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
1Netiq
1Identity Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
2Fedoraproject
Opensuse
2Fedora
Zypper
Nov 21, 2024
Mar 1, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
1Trendmicro
1Interscan Messaging Security Virtual Appliance
Nov 21, 2024
Feb 16, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be u...Show more
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on vulnerable installations.Show less
1Sap
1Hana Extended Application Services
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.
1Sensu
1Sensu Core
Nov 21, 2024
Feb 9, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data...Show more
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data (e.g. passwords) may be logged in clear-text. This attack appear to be exploitable via victims with configuration matching a specific pattern will observe sensitive data outputted in their service log files. This vulnerability appears to have been fixed in 1.2.1 and later, after commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b.Show less
1Ovirt
1Ovirt Hosted Engine Setup
Nov 21, 2024
Jan 24, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
1Linuxmagic
1Magicspam
Jun 17, 2026
Jan 14, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog.
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Jan 4, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.
1F5
1Big Ip Access Policy Manager
May 13, 2026
Dec 21, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers running debug mode log...Show more
In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers running debug mode logging with BIG-IP APM are at highest risk.Show less
1Dell
1Emc Scaleio
May 13, 2026
Nov 28, 2017
N/A· v4
8.4 HIGH· v3
2.1 LOW· v2
An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary...Show more
An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentially be read by an unprivileged user with access to the server where the script was executed to recover exposed credentials.Show less