CWE-117

Medium likelihood

Improper Output Neutralization for Logs

Parent: CWE-116 - Improper Encoding or Escaping of Output

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

93 vulnerabilities with CWE-117
CVE-2025-36625 MEDIUM
Nessus <10.8.4 - Info Disclosure
CVSS 4.3
CVE-2025-25294 MEDIUM
Envoy Gateway <1.2.7-1.3.1 - Log Injection
CVSS 5.3
CVE-2025-27111 HIGH
Rack <2.2.12, <3.0.13, <3.1.11 - Log Injection
CVSS 7.5
CVE-2025-23405 MEDIUM
Unauthenticated Log Effects - Info Disclosure
CVSS 5.3
CVE-2025-25184 MEDIUM
Rack <2.2.11, 3.0.12, 3.1.10 - Info Disclosure
CVSS 6.5
CVE-2025-0754 MEDIUM
OpenShift Service Mesh 2.6.3-2.5.6 - Log Injection
CVSS 4.3
CVE-2024-13949 MEDIUM
ASPECT <3.* - Info Disclosure
CVSS 6.8
CVE-2024-52962 MEDIUM
FortiAnalyzer <7.6.1 - Info Disclosure
CVSS 5.3
CVE-2024-9606 HIGH
berriai/litellm <1.44.12 - Info Disclosure
CVSS 7.5
CVE-2024-12580 MEDIUM
danny-avila/librechat <0.7.6 - Code Injection
CVSS 5.3
CVE-2024-49355 MEDIUM
IBM OpenPages with Watson <9.0 - Info Disclosure
CVSS 5.3
CVE-2024-56473 MEDIUM
IBM Aspera Shares <1.10.0 - SSRF
CVSS 5.3
CVE-2024-35150 MEDIUM
IBM Maximo Application Suite <9.1.0 - Info Disclosure
CVSS 5.3
CVE-2024-52891 MEDIUM
IBM Concert Software <1.0.4 - Info Disclosure
CVSS 5.4
CVE-2024-7696 MEDIUM
AXIS Camera Station - DoS
CVSS 6.3
CVE-2024-9026 LOW
PHP <8.1.30, <8.2.24, <8.3.12 - Info Disclosure
CVSS 3.3
CVE-2024-47083 HIGH
Power Platform Terraform Provider <3.0.0 - Info Disclosure
CVSS 7.5
CVE-2024-45808 MEDIUM
Envoy <1.31.2-1.28.7 - Code Injection
CVSS 6.5
CVE-2024-8334 MEDIUM
master-nan Sweet-CMS <5f441e022b8876f07cde709c77b5be6d2f262e3f - In...
CVSS 4.3
CVE-2024-8297 MEDIUM
Kitsada8621 Digital Library Management System <1.0 - Info Disclosure
CVSS 5.3
CVE-2024-23194 LOW
Gallagher Command Centre <9.10.1268 - Info Disclosure
CVSS 3.3
CVE-2024-0095 CRITICAL
Nvidia Triton Inference Server < 24.05 - Denial of Service
CVSS 9.0
CVE-2024-31845 MEDIUM
Italtel Embrace 1.6.4 - Info Disclosure
CVSS 5.3
CVE-2024-25047 HIGH
IBM Cognos Analytics <12.0.2 - Code Injection
CVSS 8.6
CVE-2024-1681 MEDIUM
flask-cors - Log Injection
CVSS 5.3
Details
Vulnerabilities 93
Exploit Likelihood Medium