← Back
CWE-532

1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,164)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kubernetes
1Secrets Store Csi Driver
Jun 17, 2026
Jun 7, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
1Hoppscotch
1Hoppscotch
Jun 17, 2026
Jun 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Attackers with access to read system logs wi...Show more
hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Attackers with access to read system logs will be able to elevate privilege with full access to the database. Users are advised to upgrade. There are no known workarounds for this vulnerability. Show less
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
1Faronics
1Insight
Jun 17, 2026
May 31, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivi...Show more
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially enabling them to obtain PII and/or to compromise personal accounts owned by the victim.Show less
1Abb
3Platform Engineering Tools
Qcs 800xa FirmwareQcs Ac450 Firmware
Jun 17, 2026
May 22, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the...Show more
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to exploit this vulnerability to gain control of system nodes. This issue affects QCS 800xA: from 1.0;0 through 6.1SP2; QCS AC450: from 1.0;0 through 5.1SP2; Platform Engineering Tools: from 1.0:0 through 2.3.0. Show less
1Jenkins
1Hashicorp Vault
Jun 17, 2026
May 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
1Mattermost
1Mattermost
Jun 17, 2026
May 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. 
1Intel
1Open Cache Acceleration Software
Jun 17, 2026
May 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a privileged user to potentially enable information disclosure via local access.
1Elastic
1Filebeat
Jun 17, 2026
May 4, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.
1Samsung
1Android
Jun 17, 2026
May 4, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
1Checkmk
1Checkmk
Jun 17, 2026
May 2, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
2Canonical
Fedoraproject
3Cloud Init
FedoraUbuntu Linux
Jun 17, 2026
Apr 26, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
1Cloverdx
1Cloverdx
Jun 17, 2026
Apr 24, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.
1Kitchen Terraform Project
1Kitchen Terraform
Jun 17, 2026
Apr 21, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform configuration and verify the resulting infrastructure systems with InSpec controls. Kitchen-Terraform...Show more
Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform configuration and verify the resulting infrastructure systems with InSpec controls. Kitchen-Terraform v7.0.0 introduced a regression which caused all Terraform output values, including sensitive values, to be printed at the `info` logging level during the `kitchen converge` action. Prior to v7.0.0, the output values were printed at the `debug` level to avoid writing sensitive values to the terminal by default. An attacker would need access to the local machine in order to gain access to these logs during an operation. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Canonical
2Cloud Init
Ubuntu Linux
Jun 17, 2026
Apr 19, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
1Canonical
1Cloud Init
Jun 17, 2026
Apr 19, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to...Show more
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.Show less
1Amazon
1Aws Sigv4
Jun 17, 2026
Apr 19, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access...Show more
aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When TRACE-level logging is enabled for an SDK, `SigningParams` is printed, thereby revealing those credentials to anyone with access to logs. All users of the AWS SDK for Rust who enabled TRACE-level logging, either globally (e.g. `RUST_LOG=trace`), or for the `aws-sigv4` crate specifically are affected. This issue has been addressed in a set of new releases. Users are advised to upgrade. Users unable to upgrade should disable TRACE-level logging for AWS Rust SDK crates. Show less
1Cilium
1Cilium
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of the `cilium-secrets` namespace. This could include data such as TLS priva...Show more
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of the `cilium-secrets` namespace. This could include data such as TLS private keys for Ingress and GatewayAPI resources. An attacker with access to debug output from the Cilium containers could use the resulting output to intercept and modify traffic to and from the affected cluster. Output of the sensitive information would occur at Cilium agent restart, when secrets in the namespace are modified, and on creation of Ingress or GatewayAPI resources. This vulnerability is fixed in Cilium releases 1.11.16, 1.12.9, and 1.13.2. Users unable to upgrade should disable debug mode.Show less
1Terminalfour
1Terminalfour
Jun 17, 2026
Apr 12, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3....Show more
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.Show less
1Gbgplc
1Acuant Asureid Sentinel
Jun 17, 2026
Apr 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify and Sentinel Installer log files, aka CORE-7362.