CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2025-25013 MEDIUM
Elastic Defend 8.0.0-8.17.2 - Sensitive Information Exposure via Unfiltered Environment Variables
CVSS 6.5
CVE-2025-25002 MEDIUM
Azure Local Cluster - Info Disclosure
CVSS 6.8
CVE-2025-32054 LOW
JetBrains IntelliJ IDEA 2024.2.4-2024.3.0 - Sensitive Information Exposure in Log File
CVSS 3.3
CVE-2025-31479 HIGH
canonical/get-workflow-version-action < 1.0.1 - Sensitive Information Disclosure in Exception Output
CVSS 8.2
CVE-2025-31788 MEDIUM
AIO Performance Profiler, Monitor, Optimize, Compress & Debug <= 1.3 - Sensitive Data Exposure via Log File Insertion
CVSS 5.3
CVE-2025-1998 MEDIUM
IBM UrbanCode Deploy <7.3.2.0 - Info Disclosure
CVSS 5.5
CVE-2025-31139 MEDIUM
JetBrains TeamCity < 2025.03 - Sensitive Information Exposure in Build Log
CVSS 4.3
CVE-2025-0273 MEDIUM
HCL DevOps Deploy/HCL Launch - Info Disclosure
CVSS 5.5
CVE-2025-20231 HIGH
Splunk Enterprise <9.4.1, 9.3.3, 9.2.5, 9.1.8 - Info Disclosure
CVSS 7.1
CVE-2025-30205 HIGH
kanidim-provision <1.2.0 - Info Disclosure
CVSS 7.6
CVE-2025-0495 MEDIUM
Docker Buildx < 0.21.3 - Sensitive Information Exposure in OpenTelemetry Traces
CVE-2025-27496 LOW
Snowflake JDBC driver <3.23.0 - Info Disclosure
CVSS 3.3
CVE-2025-2002 MEDIUM
FTP Server <debug - Info Disclosure
CVSS 6.0
CVE-2025-24984 MEDIUM KEV
Windows 10/11, Server 2012-2016 NTFS Log File Information Disclosure
CVSS 4.6
CVE-2025-0071 MEDIUM
SAP Web Dispatcher & Internet Communication Manager - Info Disclosure
CVSS 4.9
CVE-2025-1296 MEDIUM
Nomad 1.0.0-1.7.18, 1.8.0-1.9.6 - Sensitive Token Exposure in Audit Logs
CVSS 6.5
CVE-2025-1696 MEDIUM
Docker Desktop <4.39.0 - Info Disclosure
CVE-2025-1979 MEDIUM
Ray < 2.43.0 - Sensitive Information Disclosure via Redis Password Logging
CVSS 6.4
CVE-2025-1075 HIGH
Checkmk <2.3.0p27, <2.2.0p40, 2.1.0p51 - Info Disclosure
CVSS 7.5
CVE-2025-1053 MEDIUM
Brocade SANnav < 2.3.1b - Sensitive Information Disclosure in Log File
CVSS 4.9
CVE-2025-23413 MEDIUM
F5 BIG-IP Next Central Manager 20.2.0-20.2.x - Sensitive Information Disclosure in pgaudit Log Files
CVSS 4.4
CVE-2025-24556 HIGH
DualCube MooWoodle <3.2.4 - Info Disclosure
CVSS 7.5
CVE-2025-23374 HIGH
Dell Enterprise SONiC <4.2.3/<4.4.1 Authenticated Sensitive Info Exposure via Log File Insertion
CVSS 8.0
CVE-2025-24884 MEDIUM
kube-audit-rest <1.0.16 - Info Disclosure
CVE-2025-0736 MEDIUM
Infinispan - Sensitive Information Exposure in JGroups JDBC_PING Logging
CVSS 5.5
Details
Vulnerabilities 1,137
Exploit Likelihood Medium