← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Mar 30, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not nee...Show more
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-184525194Show less
1Asseco
1Dvs Avilys
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.
1Jupyter
1Jupyter Server
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Any...Show more
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter Server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server. Jupyter Server version 1.15.4 contains a patch for this issue. There are currently no known workarounds.Show less
1Tecnoteca
1Cmdbuild
Jun 17, 2026
Mar 22, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the password of the users who login to the application by querying the databa...Show more
In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the password of the users who login to the application by querying the database table.Show less
1Sophos
1Unified Threat Management
Jun 17, 2026
Mar 22, 2022
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in...Show more
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.Show less
1Google
1Android
Jun 17, 2026
Mar 16, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User intera...Show more
In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-178379135References: Upstream kernelShow less
1Redhat
1Ansible
Jun 17, 2026
Mar 16, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker t...Show more
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.Show less
1Samsung
1Galaxy Watch 3 Plugin
Jun 17, 2026
Mar 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log
1Samsung
1Watch Active2 Plugin
Jun 17, 2026
Mar 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log
1Samsung
1Watch Active Plugin
Jun 17, 2026
Mar 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log
1Samsung
1Galaxy Watch Plugin
Jun 17, 2026
Mar 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log
1Samsung
1Galaxy Watch 3 Plugin
Jun 17, 2026
Mar 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log
1Samsung
1Galaxy Watch Plugin
Jun 17, 2026
Mar 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.
2Fedoraproject
Keepass
3Extra Packages For Enterprise Linux
FedoraKeepass
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive...Show more
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.Show less
1Siemens
1Climatix Pol909 Firmware
Jun 17, 2026
Mar 8, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices cont...Show more
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.Show less
1Correosexpress Project
1Correosexpress
Jun 17, 2026
Mar 7, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
1Hashicorp
1Terraform Enterprise
Jun 17, 2026
Feb 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
1Cisco
1Catalyst Center
Jun 17, 2026
Feb 10, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information o...Show more
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials.Show less
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Feb 10, 2022
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Conn...Show more
An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect App 5.2 versions earlier than 5.2.9 on Windows. This issue does not affect the GlobalProtect app on other platforms.Show less
1Vmware
1Cloud Foundation
Jun 17, 2026
Feb 4, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Found...Show more
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in plaintext within one or more log files.Show less