CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3.4.109, 4.0.027.13, 4.0.125 and 5.0.013.0. |
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property whe...Show more |
3Opensuse SuseYast2 Rmt Project3Leap Suse Linux Enterprise ServerYast2 RmtNov 21, 2024 Jan 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affe...Show more |
1Simplesamlphp 1Simplesamlphp Jun 17, 2026 Jan 24, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the system administrator, did not properly sanitize the report identifier obta...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnJun 17, 2026 Jan 23, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI...Show more |
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR...Show more |
In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts are customized during installation or upgrade of PI Vision. The update fixes a pre...Show more |
1Pivotal Software 1Operations Manager Jun 17, 2026 Jan 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jan 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret mater...Show more |
3Debian OpensuseRedhat8Ansible Ansible TowerBackports Sle+5 moreJun 17, 2026 Jan 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results e...Show more |
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information. |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Dec 23, 2019 N/A· v4 4.9 MEDIUM· v3 3.5 LOW· v2 On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session policy is attached to the virtual server...Show more |
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/local/cwpsrv/logs/acce...Show more |
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp directory, and the victim's token value from /usr/local/cwpsrv/logs/access_l...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Dec 15, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration |
1Puppet 1Continuous Delivery Jun 17, 2026 Dec 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details pane in the PE console. These issues have...Show more |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationJun 17, 2026 Dec 6, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user crede...Show more |
2Fedoraproject Freeipa2Fedora FreeipaJun 17, 2026 Nov 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user...Show more |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationJun 17, 2026 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. |
1Redhat 1Openshift Container Platform Jun 17, 2026 Nov 25, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discove...Show more |