← Back
CWE-532

1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,164)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Jun 17, 2026
Nov 21, 2019
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values...Show more
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team disputes this issues as not being a vulnerability because “1) The kernel provide facilities to restrict access to dmesg - dmesg_restrict=1 sysctl option. So it's really up to the system administrator to judge whether dmesg access shall be disallowed or not. 2) WARN/WARN_ON are widely used macros in the linux kernel. If this CVE is considered valid this would mean there are literally thousands CVE lurking in the kernel - something which clearly is not the case.Show less
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Jun 17, 2026
Nov 15, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that...Show more
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.Show less
3Fedoraproject
MoodleRedhat
3Enterprise Linux
FedoraMoodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moodle before 2.2.2 has users' private files included in course backups
1Mcafee
1Advanced Threat Defense
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incor...Show more
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incorrectly recorded data from log files.Show less
1Broadcom
1Brocade Sannav
Jun 17, 2026
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
1Broadcom
1Brocade Sannav
Jun 17, 2026
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive...Show more
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.Show less
1Monkey Project
1Monkey
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
1Apache
1Impala
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
4.6 MEDIUM· v2
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query IDs are unique and random, but have not been documented or consistently treated as sensitive secrets. Therefore they may be exposed in logs or interfaces. They were also not generated with a cryptographically secure random number generator, so are vulnerable to random number generator attacks that predict future IDs based on past IDs. Impala deployments with Apache Sentry or Apache Ranger authorization enabled may be vulnerable to privilege escalation if an authenticated attacker is able to hijack a session or query from another authenticated user with privileges not assigned to the attacker. Impala deployments with audit logging enabled may be vulnerable to incorrect audit logging as a user could undertake actions that were logged under the name of a different authenticated user. Constructing an attack requires a high degree of technical sophistication and access to the Impala system as an authenticated user.Show less
1Terra Master
1Fs 210 Firmware
Jun 17, 2026
Oct 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.
2Cloudfoundry
Pivotal Software
2Cf Deployment
Cloud Foundry Smb Volume
Jun 17, 2026
Oct 23, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have be...Show more
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.Show less
1Rapidgator
1Rapidgator
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Darkhorse
1Dark Horse Comics
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat.
1Powerschool
1Powerschool Mobile
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Seesaw
1Parent And Family
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Orbitz
1Orbitz
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Doordash
1Doordash
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
1Redhat
2Ansible Engine
Ansible Tower
Jun 17, 2026
Oct 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cau...Show more
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.Show less
1Ibm
1Filenet Content Manager
Jun 17, 2026
Oct 14, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine. IBM X-Force ID: 166798.
1Sap
1Landscape Management
Jun 17, 2026
Oct 8, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
3Debian
OpensuseRedhat
5Ansible Engine
Backports SleDebian Linux+2 more
Jun 17, 2026
Oct 8, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that...Show more
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.Show less