CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2025-5464 MEDIUM
Ivanti Connect Secure <22.7R2.8 - Info Disclosure
CVSS 6.5
CVE-2025-5463 MEDIUM
Ivanti Connect/Ivanti Policy <22.7R2.8/<22.7R1.5 - Info Disclosure
CVSS 5.5
CVE-2025-6711 MEDIUM
MongoDB 6.0.0-6.0.20 - Sensitive Information Exposure in Server Logs
CVSS 4.4
CVE-2025-49846 MEDIUM
Wire iOS <3.124.1 - Info Disclosure
CVE-2025-6587 MEDIUM
Docker Desktop <4.43.0 - Info Disclosure
CVE-2025-6624 HIGH
Snyk CLI < 1.1297.3 - Sensitive Information Exposure in Debug Logs
CVSS 7.2
CVE-2025-52893 MEDIUM
OpenBao < 2.3.0 - Sensitive Information Exposure in Error Logs via Malformed Data Processing
CVSS 4.5
CVE-2025-36050 MEDIUM
IBM QRadar SIEM 7.5-7.5.0 Update Package 12 - Sensitive Information Disclosure in Log Files
CVSS 6.2
CVE-2025-50200 MEDIUM
RabbitMQ < 4.0.8 - Sensitive Information Disclosure in Log Files
CVSS 5.5
CVE-2025-2327 MEDIUM
Pure Storage FlashArray <=6.8.4 Key Encryption Key Exposure in Log Files
CVE-2025-36573 HIGH
Dell Pro Smart Dock SD25/SD25TB4 < 01.00.08.01 - Information Disclosure via Log File Insertion
CVSS 7.1
CVE-2025-49009 MEDIUM
Para < 1.50.8 - Sensitive Information Exposure in FacebookAuthFilter Log
CVSS 6.2
CVE-2025-48493 MEDIUM
Yii 2 Redis Extension <2.0.20 - Info Disclosure
CVSS 6.5
CVE-2025-48955 MEDIUM
Para < 1.50.8 - Sensitive Information Exposure in Log Files
CVSS 6.2
CVE-2025-31199 MEDIUM
iPadOS < 18.4 - Sensitive Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2025-46777 LOW
Fortinet FortiPortal <7.4.0 - Info Disclosure
CVSS 2.3
CVE-2025-48374 MEDIUM
zot < 1.4.4-0.20250522160828-8a99a3ed231f - Sensitive Information Exposure in Logs via Keycloak OIDC Client Secret
CVE-2025-26864 HIGH
Apache IoTDB 0.10.0-1.3.3 and 2.0.1-beta - Sensitive Information Exposure via OpenIdAuthorizer
CVSS 7.5
CVE-2025-26795 HIGH
Apache IoTDB JDBC Driver 0.10.0-1.3.3 and 2.0.1-beta - Sensitive Information Exposure via Log File Insertion
CVSS 7.5
CVE-2025-22246 LOW
Cloud Foundry UAA <7.32 - Info Disclosure
CVSS 3.0
CVE-2025-31213 HIGH
iPadOS < 17.7.7 and macOS < 13.7.6, < 14.7.6, < 15.5 - Sensitive Information Disclosure in Log Files
CVSS 7.6
CVE-2025-3911 MEDIUM
Docker Desktop <4.40.9 - Info Disclosure
CVE-2025-4090 MEDIUM
Firefox and Thunderbird < 138.0 - Sensitive Information Exposure via Logcat
CVSS 5.3
CVE-2025-46329 LOW
libsnowflakeclient <2.2.0 - Info Disclosure
CVSS 3.3
CVE-2025-46614 LOW
Snowflake ODBC Driver <3.7.0 - Info Disclosure
CVSS 3.3
Details
Vulnerabilities 1,170
Exploit Likelihood Medium