CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Redhat7Active Iq Unified Manager Jboss Data GridJboss Enterprise Application Platform+4 moreJun 17, 2026 Oct 2, 2019 N/A· v4 9.8 CRITICAL· v3 4.3 MEDIUM· v2 A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files. |
1Enterprisedt 1Completeftp Server Jun 17, 2026 Oct 2, 2019 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash. |
In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interactio...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Access Policy Manager ClientJun 17, 2026 Sep 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0...Show more |
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed t...Show more |
1Dell 2Rsa Identity Governance And Lifecycle Rsa Via Lifecycle And GovernanceJun 17, 2026 Sep 11, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability. The Office 365 user password may get logged in a plain te...Show more |
1Couchbase 1Couchbase Server Jun 17, 2026 Sep 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug repo...Show more |
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT cr...Show more |
2F5 Redhat2Container Ingress Service OpenshiftJun 17, 2026 Sep 4, 2019 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphr...Show more |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Aug 29, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) pri...Show more |
1Gallagher 1Command Centre Jun 17, 2026 Aug 28, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password fo...Show more |
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request p...Show more |
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request...Show more |
An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to th...Show more |
OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information. |
1Swann 1Swwhd Intcam Hd Firmware Nov 21, 2024 Aug 8, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31. |
1Cisco 1Enterprise Network Function Virtualization Infrastructure Jun 17, 2026 Aug 8, 2019 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerabili...Show more |
1Cisco 1Enterprise Network Function Virtualization Infrastructure Jun 17, 2026 Aug 8, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging th...Show more |
Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure. |
Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied. |