CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password. |
1Mattermost 1Mattermost Mobile Jun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content). |
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system. IBM X-Force ID: 181779. |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jun 12, 2020 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an...Show more |
GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs. |
1Philips 1Intellibridge Enterprise Jun 17, 2026 Jun 11, 2020 N/A· v4 4.5 MEDIUM· v3 2.7 LOW· v2 Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in t...Show more |
HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2. |
4Arista CanonicalDebian+1 more4Cloudvision Portal Debian LinuxPam Tacplus+1 moreJun 17, 2026 Jun 6, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. |
An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020). |
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. This presents a probl...Show more |
1Cisco 1Digital Network Architecture Center Jun 17, 2026 Jun 3, 2020 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the...Show more |
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG. |
1Paloaltonetworks 1Globalprotect Jun 17, 2026 May 13, 2020 N/A· v4 5.5 MEDIUM· v3 1.7 LOW· v2 Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS an...Show more |
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered. |
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality. |
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514. |
1Redhat 1Openshift Container Platform Jun 17, 2026 Apr 22, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and writ...Show more |
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after ini...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Apr 14, 2020 N/A· v4 6.2 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs...Show more |
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Junos OS Evolved prior to 19.1R1. |