CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it. |
In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can re...Show more |
1Puppet 3Puppet Puppet ConnectPuppet EnterpriseJun 17, 2026 Nov 18, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged |
1Intel 18Ssd D S4510 Firmware Ssd D5 P4320 FirmwareSsd D5 P4326 Firmware+15 moreJun 17, 2026 Nov 17, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access. |
1Binatoneglobal 21Cn28 Firmware Cn40 FirmwareCn50 Firmware+18 moreJun 17, 2026 Nov 12, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive...Show more |
1Siemens 2Simatic Pcs 7 Simatic WinccJun 17, 2026 Nov 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15...Show more |
1Siemens 1Simatic Rtls Locating Manager Jun 17, 2026 Nov 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as usernames and passwords in log files. A local attacker with access to t...Show more |
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an at...Show more |
An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs. |
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs. |
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an at...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Guided ConfigurationJun 17, 2026 Sep 14, 2021 N/A· v4 4.9 MEDIUM· v3 3.5 LOW· v2 On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. N...Show more |
1Check Spelling 1Check Spelling Jun 17, 2026 Sep 9, 2021 N/A· v4 9.9 CRITICAL· v3 6.8 MEDIUM· v2 check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https://github.com/marketplace/actions/check-spelling) enabled that triggers...Show more |
Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionalit...Show more |
1Puppet 2Puppet Puppet EnterpriseJun 17, 2026 Sep 7, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory s...Show more |
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log. |
1Puppet 2Puppet Enterprise PuppetdbJun 17, 2026 Aug 30, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 PuppetDB logging included potentially sensitive system information. |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log fil...Show more |
1Netmodule 1Netmodule Router Software Jun 17, 2026 Aug 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800...Show more |
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch....Show more |