← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Abb
3Platform Engineering Tools
Qcs 800xa FirmwareQcs Ac450 Firmware
Jun 17, 2026
May 22, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the...Show more
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to exploit this vulnerability to gain control of system nodes. This issue affects QCS 800xA: from 1.0;0 through 6.1SP2; QCS AC450: from 1.0;0 through 5.1SP2; Platform Engineering Tools: from 1.0:0 through 2.3.0. Show less
1Jenkins
1Hashicorp Vault
Jun 17, 2026
May 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
1Mattermost
1Mattermost
Jun 17, 2026
May 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. 
1Intel
1Open Cache Acceleration Software
Jun 17, 2026
May 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a privileged user to potentially enable information disclosure via local access.
1Elastic
1Filebeat
Jun 17, 2026
May 4, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.
1Samsung
1Android
Jun 17, 2026
May 4, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
1Checkmk
1Checkmk
Jun 17, 2026
May 2, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
2Canonical
Fedoraproject
3Cloud Init
FedoraUbuntu Linux
Jun 17, 2026
Apr 26, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
1Cloverdx
1Cloverdx
Jun 17, 2026
Apr 24, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.
1Kitchen Terraform Project
1Kitchen Terraform
Jun 17, 2026
Apr 21, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform configuration and verify the resulting infrastructure systems with InSpec controls. Kitchen-Terraform...Show more
Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform configuration and verify the resulting infrastructure systems with InSpec controls. Kitchen-Terraform v7.0.0 introduced a regression which caused all Terraform output values, including sensitive values, to be printed at the `info` logging level during the `kitchen converge` action. Prior to v7.0.0, the output values were printed at the `debug` level to avoid writing sensitive values to the terminal by default. An attacker would need access to the local machine in order to gain access to these logs during an operation. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Canonical
2Cloud Init
Ubuntu Linux
Jun 17, 2026
Apr 19, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
1Canonical
1Cloud Init
Jun 17, 2026
Apr 19, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to...Show more
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.Show less
1Amazon
1Aws Sigv4
Jun 17, 2026
Apr 19, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access...Show more
aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When TRACE-level logging is enabled for an SDK, `SigningParams` is printed, thereby revealing those credentials to anyone with access to logs. All users of the AWS SDK for Rust who enabled TRACE-level logging, either globally (e.g. `RUST_LOG=trace`), or for the `aws-sigv4` crate specifically are affected. This issue has been addressed in a set of new releases. Users are advised to upgrade. Users unable to upgrade should disable TRACE-level logging for AWS Rust SDK crates. Show less
1Cilium
1Cilium
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of the `cilium-secrets` namespace. This could include data such as TLS priva...Show more
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of the `cilium-secrets` namespace. This could include data such as TLS private keys for Ingress and GatewayAPI resources. An attacker with access to debug output from the Cilium containers could use the resulting output to intercept and modify traffic to and from the affected cluster. Output of the sensitive information would occur at Cilium agent restart, when secrets in the namespace are modified, and on creation of Ingress or GatewayAPI resources. This vulnerability is fixed in Cilium releases 1.11.16, 1.12.9, and 1.13.2. Users unable to upgrade should disable debug mode.Show less
1Terminalfour
1Terminalfour
Jun 17, 2026
Apr 12, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3....Show more
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.Show less
1Gbgplc
1Acuant Asureid Sentinel
Jun 17, 2026
Apr 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify and Sentinel Installer log files, aka CORE-7362.
1Jetbrains
1Phpstorm
Jun 17, 2026
Apr 4, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
1Hitachi
1Vantara Pentaho Business Analytics Server
Jun 17, 2026
Apr 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs. 
1F5
2Nginx Agent
Nginx Instance Manager
Jun 17, 2026
Mar 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agen...Show more
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.Show less
1Veracode
1Veracode
Jun 17, 2026
Mar 28, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configu...Show more
Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to view the job log) to discover proxy credentials.Show less