CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph R...Show more |
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3,...Show more |
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry c...Show more |
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3. |
In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This information although sen...Show more |
1Ibm 1Business Automation Workflow Jun 17, 2026 Nov 30, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 190991. |
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file. |
2Heketi Project Redhat4Enterprise Linux Gluster StorageHeketi+1 moreJun 17, 2026 Nov 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as g...Show more |
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable...Show more |
1Ibm 1Sterling B2b Integrator Jun 17, 2026 Nov 16, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an authenticatedl user. IBM X-Force ID: 186284. |
An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS...Show more |
1Br Automation 3Gatemanager 4260 Firmware Gatemanager 8250 FirmwareGatemanager 9250 FirmwareJun 17, 2026 Oct 15, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view log information reserved for other users. |
1Br Automation 3Gatemanager 4260 Firmware Gatemanager 8250 FirmwareGatemanager 9250 FirmwareJun 17, 2026 Oct 15, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign dom...Show more |
1Dell 1Emc Openmanage Integration For Microsoft System Center Jun 17, 2026 Oct 8, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vulnerability. Authenticated low privileged OMIMSCC users may be able to...Show more |
An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attackers to obtain sensitive information by reading a log. The Samsung ID is SVE-2020-18596 (October 2020...Show more |
MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash. |
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentiall...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log fil...Show more |
2Debian Redhat2Ansible Engine Debian LinuxJun 17, 2026 Sep 11, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to rea...Show more |
2Debian Redhat2Ansible Engine Debian LinuxJun 17, 2026 Sep 11, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of pe...Show more |