CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2025-24169 HIGH
Safari < 18.3 and macOS < 15.3 - Sensitive Information Disclosure via Log File
CVSS 7.5
CVE-2025-24145 LOW
iPadOS < 18.3 - Unprotected Contact Phone Number Exposure in System Logs
CVSS 3.3
CVE-2025-24389 MEDIUM
OTRS 7.0.x 8.0.x 2023.x 2024.x and ((OTRS)) Community Edition < 6.0.34 - Sensitive Information Disclosure in Log Files
CVSS 6.3
CVE-2025-24362 HIGH
github/codeql-action 3.26.11-3.28.2 and 2.26.11-<3 - Information Exposure via Debug Artifact
CVE-2025-24034 LOW
Himmelblau <0.7.15 & 0.8.3 - Info Disclosure
CVSS 3.2
CVE-2025-24457 MEDIUM
JetBrains YouTrack < 2024.3.55417 - Sensitive Information Exposure via Log File Insertion
CVSS 5.5
CVE-2025-21323 MEDIUM
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2016-2019 - Kernel Memory Information Disclosure
CVSS 5.5
CVE-2025-21321 MEDIUM
Windows Kernel - Information Disclosure via Memory Log Insertion
CVSS 5.5
CVE-2025-21320 MEDIUM
Windows 10 1507-24H2 and Windows Server 2008-2012 - Kernel Memory Information Disclosure
CVSS 5.5
CVE-2025-21319 MEDIUM
Windows 10 1507-24H2 and Windows Server 2008-2012 - Kernel Memory Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2025-21318 MEDIUM
Windows 10 1507-24H2 and Windows Server 2012-2016 - Kernel Memory Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2025-21317 MEDIUM
Windows Kernel - Information Disclosure via Memory Log Insertion
CVSS 5.5
CVE-2025-21316 MEDIUM
Windows 10 1507-24H2 and Windows Server 2012-2016 - Kernel Memory Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2025-22275 CRITICAL
iTerm2 3.5.6-3.5.10 - Sensitive Information Exposure via /tmp/framer.txt
CVSS 9.3
CVE-2024-30151 HIGH
HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability
CVSS 8.3
CVE-2024-11604 HIGH
Insertion of Sensitive Information into Log File
CVE-2024-47570 MEDIUM
FortiOS <7.4.3, <7.2.7, <=7.0 - Info Disclosure
CVSS 6.6
CVE-2024-58269 MEDIUM
Rancher < 0.0.0-20251013203444-50dc516a19ea - Sensitive Information Exposure in Audit Logs
CVSS 4.3
CVE-2024-9453 MEDIUM
Jenkins - Sensitive Information Exposure via Unobfuscated Bearer Token in Logs
CVSS 6.5
CVE-2024-7586 MEDIUM
GitLab 17.0-17.0.6, 17.1-17.1.4, 17.2-17.2.2 - Sensitive Information Exposure in Webhook Deletion Audit Log
CVSS 4.1
CVE-2024-7577 MEDIUM
IBM InfoSphere Information Server 11.7 - Sensitive Credential Exposure in Log Files
CVSS 4.4
CVE-2024-40585 MEDIUM
FortiManager/FortiAnalyzer <7.4.0 - Info Disclosure
CVSS 6.5
CVE-2024-45674 LOW
IBM Security Verify Bridge Directory Sync 1.0.1-1.0.12 - Sensitive Information Disclosure in Log Files
CVSS 3.3
CVE-2024-13818 MEDIUM
Pie Register < 3.8.4 - Unauthenticated Sensitive Information Exposure via Publicly Exposed Log Files
CVSS 5.3
CVE-2024-13416 MEDIUM
2N OS <= 2.45 - Authenticated Sensitive Information Disclosure in System Log
CVSS 4.3
Details
Vulnerabilities 1,137
Exploit Likelihood Medium