← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
1Emc Unity Operating Environment
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.
1Loguru Project
1Loguru
Jun 17, 2026
Jan 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
1M Files
1M Files Server
Jun 17, 2026
Jan 18, 2022
N/A· v4
2.3 LOW· v3
1.9 LOW· v2
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
1Stormshield
1Network Security
Jun 17, 2026
Jan 17, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
1Sap
1Business One
Jun 17, 2026
Jan 14, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
1Ibm
1Sterling Gentran
Jun 17, 2026
Jan 14, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 213962.
1Docker
1Docker Desktop
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and th...Show more
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files.Show less
1Siemens
4Cp 8000 Master Module With I/o 25/+70 Firmware
Cp 8000 Master Module With I/o 40/+70 FirmwareCp 8021 Master Module Firmware+1 more
Jun 17, 2026
Jan 11, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP...Show more
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows access to logfiles and diagnostic data generated by a privileged user. An unauthenticated attacker could access the files by knowing the corresponding download links.Show less
1Apache
1Geode
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security pro...Show more
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.Show less
1Dell
1Emc Avamar Server
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.
1Google
1Android
Jun 17, 2026
Dec 15, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution priv...Show more
In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191086488Show less
1Google
1Android
Jun 17, 2026
Dec 15, 2021
N/A· v4
2.4 LOW· v3
2.7 LOW· v2
In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with S...Show more
In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181588752Show less
1Mattermost
1Mattermost
Jun 17, 2026
Dec 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
1Acronis
1Agent
Jun 17, 2026
Nov 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147
1Dell
1Emc Powerscale Onefs
Jun 17, 2026
Nov 23, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive...Show more
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files.Show less
1Huawei
2Ecns280 Td Firmware
Fusioncompute
Jun 17, 2026
Nov 23, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information...Show more
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.Show less
1Dell
1Secure Connect Gateway
Jun 17, 2026
Nov 20, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.
1Greenplum
1Greenplum
Jun 17, 2026
Nov 19, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can re...Show more
In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can read sensitive(credentials) information about usersShow less
1Puppet
3Puppet
Puppet ConnectPuppet Enterprise
Jun 17, 2026
Nov 18, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
1Intel
18Ssd D S4510 Firmware
Ssd D5 P4320 FirmwareSsd D5 P4326 Firmware+15 more
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access.