CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2024-57957 MEDIUM
HarmonyOS - Sensitive Information Exposure via UI Framework Log Insertion
CVSS 6.6
CVE-2024-48852 CRITICAL
ABB FLXEON <= 9.3.4 - Sensitive Information Disclosure via Log File Insertion
CVSS 9.4
CVE-2024-54519 MEDIUM
macOS < 14.7.2 and < 15.2 - Sensitive Location Information Exposure via Log File
CVSS 5.5
CVE-2024-45091 MEDIUM
IBM UrbanCode Deploy <7.0.5.24-7.1.2.10-7.2.3.13 - Info Disclosure
CVSS 6.2
CVE-2024-11923 MEDIUM
Fortra Application Hub <1.3 - Info Disclosure
CVSS 5.5
CVE-2024-12226 MEDIUM
Octopus Kubernetes <2 - Info Disclosure
CVSS 6.5
CVE-2024-55891 LOW
TYPO3 13.4.2 - Insertion of Sensitive Information into Log File
CVSS 3.1
CVE-2024-40679 MEDIUM
IBM Db2 11.5 - Sensitive Information Disclosure in Log File
CVSS 5.5
CVE-2024-12569 HIGH
Milestone XProtect - Info Disclosure
CVSS 7.8
CVE-2024-49816 MEDIUM
IBM Security Guardium Key Lifecycle Manager <4.2.1 - Info Disclosure
CVSS 4.9
CVE-2024-12292 MEDIUM
GitLab 11.0-17.4.5, 17.5-17.5.3, 17.6-17.6.1 - Sensitive Information Disclosure in GraphQL Logs
CVSS 4.0
CVE-2024-54484 MEDIUM
macOS < 15.2 - Unprotected User Data Exposure via Log File Insertion
CVSS 5.5
CVE-2024-42407 HIGH
Gallagher Command Centre <9.10.2149, <9.00.2374, <8.90.2356, <=8.80...
CVSS 8.5
CVE-2024-12057 LOW
PcVue 15.0.0-15.2.10 and 16.0.0-16.2.3 - Sensitive Information Disclosure in Log Files
CVE-2024-55578 MEDIUM
Zammad < 6.4.1 - Sensitive Information Exposure in Log Files
CVSS 4.3
CVE-2024-42196 MEDIUM
HCL Launch 7.0.0.0-7.0.5.25 - Sensitive Information Exposure in Log Files
CVSS 6.2
CVE-2024-47094 MEDIUM
Checkmk <2.3.0p22-<2.1.0p50 - Info Disclosure
CVSS 5.5
CVE-2024-52067 MEDIUM
Apache NiFi <2.0.0-M4 - Info Disclosure
CVSS 4.9
CVE-2024-52940 HIGH
AnyDesk <= 8.1.0 - Sensitive Information Exposure via Direct Connection Traffic
CVSS 7.5
CVE-2024-11193 MEDIUM
Yugabyte Anywhere - Info Disclosure
CVSS 6.5
CVE-2024-11165 MEDIUM
YugabyteDB Anywhere <2.20.7.0-<2.23.0.0 - Info Disclosure
CVE-2024-52009 CRITICAL
Atlantis < 0.30.0 - Sensitive Information Disclosure in Log Files
CVSS 9.8
CVE-2024-51753 LOW
authkit-remix < 0.4.1 - Sensitive Information Exposure via Debug Log
CVE-2024-51752 MEDIUM
workos/authkit-nextjs < 0.13.2 - Sensitive Information Disclosure via Debug Log
CVSS 5.5
CVE-2024-51528 MEDIUM
Super Home Screen - Info Disclosure
CVSS 4.0
Details
Vulnerabilities 1,137
Exploit Likelihood Medium