← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jan 18, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3
-
-
Jun 17, 2026
Jan 16, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this co...Show more
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.Show less
1Typo3
1Typo3
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect....Show more
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYPO3 versions 13.4.3 ELTS which fixes the problem described. There are no known workarounds for this vulnerability.Show less
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Memory Information Disclosure Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Memory Information Disclosure Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Memory Information Disclosure Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Memory Information Disclosure Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Memory Information Disclosure Vulnerability
1Microsoft
8Windows 10 21h2
Windows 10 22h2Windows 11 22h2+5 more
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Memory Information Disclosure Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Memory Information Disclosure Vulnerability
1Ibm
1Db2
Jun 17, 2026
Jan 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
1Iterm2
1Iterm2
Jun 17, 2026
Jan 3, 2025
N/A· v4
9.3 CRITICAL· v3
N/A· v2
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integratio...Show more
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.Show less
-
-
Jun 17, 2026
Dec 19, 2024
5.2 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions.
1Ibm
1Security Guardium Key Lifecycle Manager
Jun 17, 2026
Dec 17, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
1Gitlab
1Gitlab
Jun 17, 2026
Dec 12, 2024
N/A· v4
4.0 MEDIUM· v3
N/A· v2
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL...Show more
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.Show less
1Apple
1Macos
Jun 17, 2026
Dec 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.
-
-
Jun 17, 2026
Dec 12, 2024
N/A· v4
8.5 HIGH· v3
N/A· v2
Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have no...Show more
Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access. This issue affects: Command Centre Server 9.10 prior to 9.10.2149 (MR4), 9.00 prior to 9.00.2374 (MR5), 8.90 prior to 8.90.2356 (MR6), all versions of 8.80 and prior.Show less
-
-
Jun 17, 2026
Dec 9, 2024
1.8 LOW· v4
N/A· v3
N/A· v2
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerabili...Show more
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.Show less
1Zammad
1Zammad
Jun 17, 2026
Dec 9, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Dec 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.