CWE-532
1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,220)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log. |
Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission. |
Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when configured to use local, RADIUS, or TACACS authentication) logs usernames and pass...Show more |
1Cisco 1Telepresence Video Communication Server Jun 17, 2026 May 27, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or d...Show more |
1Cisco 1Telepresence Video Communication Server Jun 17, 2026 May 27, 2022 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or d...Show more |
1Cisco 1Telepresence Video Communication Server Jun 17, 2026 May 26, 2022 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or d...Show more |
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible |
An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authenticated, local attacker to view sensitive information such as ssh passwords in filetansfe...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 May 5, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh and nethsm-thales-install.sh) expose the Net HSM partition password. N...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Access Policy Manager ClientJun 17, 2026 May 5, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM C...Show more |
3Debian FedoraprojectSamba3Cifs Utils Debian LinuxFedoraJun 17, 2026 Apr 28, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 27, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037. |
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter. |
Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1. |
The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and including 1.1.1 the `org.conroller.js` code would erroneously log user secrets. This has been resolved in...Show more |
1Microsoft 1Azure Sdk For .net Jun 17, 2026 Apr 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Azure SDK for .NET Information Disclosure Vulnerability |
Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged |
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer. |
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password. |
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the aut...Show more |