← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rocketchat
1Rocket.chat
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs.
1Jetbrains
1Teamcity
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable fil...Show more
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.Show less
1Samsung
1Samsung Members
Jun 17, 2026
Sep 9, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.
1Dell
1Emc Powerscale Onefs
Jun 17, 2026
Sep 2, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentia...Show more
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to exposure of this sensitive data.Show less
1Hp
1Oneview
Jun 17, 2026
Aug 31, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive informatio...Show more
A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality, integrity, and availability. To exploit this vulnerability, HPE OneView must be configured with credential access to external repositories. HPE has provided a software update to resolve this vulnerability in HPE OneView.Show less
2Gnu
Netapp
7Glibc
H300s FirmwareH410c Firmware+4 more
Jun 17, 2026
Aug 31, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log fil...Show more
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.Show less
3Debian
OpenstackRedhat
4Debian Linux
Openshift Container PlatformOpenstack Platform+1 more
Jun 17, 2026
Aug 29, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
1Ericsson
1Network Manager
Jun 17, 2026
Aug 26, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in EN...Show more
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized by the Security Administrator. Those users can access some log’s files, under a common path, and read information stored in the log’s files in order to conduct privilege escalation.Show less
1Elastic
1Elastic Cloud Enterprise
Jun 17, 2026
Aug 25, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in t...Show more
A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are PATCH /api/v1/user and PATCH /deployments/{deployment_id}/elasticsearch/{ref_id}/keystoreShow less
1Qualys
1Cloud Agent
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (from environment variab...Show more
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (from environment variables) to disk in cleartext. NOTE: there are no common circumstances in which qualys-cloud-agent-scan.log can be read by a user other than root; however, the file contents could be exposed through site-specific operational practices. The vendor does NOT characterize this as a vulnerability because the ps data collection is intentional, and would only capture credentials on a machine that was already affected by the CWE-214 weaknessShow less
1Hashicorp
1Consul Template
Jun 17, 2026
Aug 17, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorr...Show more
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.Show less
1Google
1Android
Jun 17, 2026
Aug 12, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User inter...Show more
In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-205130113Show less
1Vmware
1Vrealize Operations
Jun 17, 2026
Aug 10, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 10, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
1Arista
1Cloudvision Portal
Jun 17, 2026
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and Syst...Show more
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.Show less
1Nextcloud
1Mail
Jun 17, 2026
Aug 4, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail would log user passwords to disk in the event of a misconfiguration. Should an attacker gain access to...Show more
Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail would log user passwords to disk in the event of a misconfiguration. Should an attacker gain access to the logs complete access to affected accounts would be obtainable. It is recommended that the Nextcloud Mail is upgraded to 1.12.1. Operators should inspect their logs and remove passwords which have been logged. There are no workarounds to prevent logging in the event of a misconfiguration.Show less
1Next Auth
1Nextauth.js
Jun 17, 2026
Aug 1, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulnerability in `next-auth` before `v4.10.2` and `v3.29.9` allows an attacker with log access privilege t...Show more
NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulnerability in `next-auth` before `v4.10.2` and `v3.29.9` allows an attacker with log access privilege to obtain excessive information such as an identity provider's secret in the log (which is thrown during OAuth error handling) and use it to leverage further attacks on the system, like impersonating the client to ask for extensive permissions. This issue has been patched in `v4.10.2` and `v3.29.9` by moving the log for `provider` information to the debug level. In addition, we added a warning for having the `debug: true` option turned on in production. If for some reason you cannot upgrade, you can user the `logger` configuration option by sanitizing the logs.Show less
1Wavlink
1Wl Wn579x3 Firmware
Jun 17, 2026
Jul 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.
1Couchbase
1Couchbase Server
Jun 17, 2026
Jul 21, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.