CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2024-52067 MEDIUM
Apache NiFi <2.0.0-M4 - Info Disclosure
CVSS 4.9
CVE-2024-52940 HIGH
AnyDesk <= 8.1.0 - Sensitive Information Exposure via Direct Connection Traffic
CVSS 7.5
CVE-2024-11193 MEDIUM
Yugabyte Anywhere - Info Disclosure
CVSS 6.5
CVE-2024-11165 MEDIUM
YugabyteDB Anywhere <2.20.7.0-<2.23.0.0 - Info Disclosure
CVE-2024-52009 CRITICAL
Atlantis < 0.30.0 - Sensitive Information Disclosure in Log Files
CVSS 9.8
CVE-2024-51753 LOW
authkit-remix < 0.4.1 - Sensitive Information Exposure via Debug Log
CVE-2024-51752 MEDIUM
workos/authkit-nextjs < 0.13.2 - Sensitive Information Disclosure via Debug Log
CVSS 5.5
CVE-2024-51528 MEDIUM
Super Home Screen - Info Disclosure
CVSS 4.0
CVE-2024-10544 MEDIUM
Woo Manage Fraud Orders <6.1.7 - Info Disclosure
CVSS 5.3
CVE-2024-44239 MEDIUM
iPadOS < 17.7.1 - Sensitive Kernel State Exposure via Log File
CVSS 5.5
CVE-2024-27849 LOW
macOS Sequoia <15 - Info Disclosure
CVSS 3.3
CVE-2024-49750 MEDIUM
Snowflake Connector for Python <3.12.3 - Info Disclosure
CVSS 5.5
CVE-2024-44205 MEDIUM
iPadOS < 16.7.9 - Sensitive Information Exposure in System Logs
CVSS 5.5
CVE-2024-45739 MEDIUM
Splunk < 9.3.1, < 9.2.3, < 9.1.6 - Plaintext Password Exposure in AdminManager Debug Log
CVSS 4.9
CVE-2024-45738 MEDIUM
Splunk 9.1.0-9.1.5 - Sensitive Information Exposure via REST_Calls Log Channel
CVSS 4.9
CVE-2024-38862 MEDIUM
Checkmk <2.3.0p18, <2.2.0p35, <2.1.0p48, <=2.0.0p39 - Sensitive Information Disclosure in Audit Log
CVSS 4.4
CVE-2024-8264 MEDIUM
Fortra's Robot Schedule Enterprise Agent <3.05 - Info Disclosure
CVSS 5.5
CVE-2024-9466 MEDIUM
Palo Alto Networks Expedition 1.2.0-1.2.95 - Authenticated Sensitive Information Disclosure in Log Files
CVSS 6.5
CVE-2024-47822 MEDIUM
Directus < 10.13.2 - Sensitive Information Exposure in Log Files via Query String Access Token
CVSS 4.2
CVE-2024-9621 MEDIUM
Quarkus CXF - Sensitive Information Disclosure in Log Files
CVSS 5.3
CVE-2024-47913 MEDIUM
MediaWiki AbuseFilter <1.39.9, 1.40.x-1.41.x<1.41.3, 1.42.x<1.42.2 - API Unauthorized Log Disclosure
CVSS 5.3
CVE-2024-20491 MEDIUM
Cisco Nexus Dashboard Insights - Info Disclosure
CVSS 6.3
CVE-2024-20490 MEDIUM
Cisco Nexus Dashboard - Info Disclosure
CVSS 6.3
CVE-2024-8609 HIGH
Oceanic Software ValeApp <2.0.0 - Info Disclosure
CVSS 7.5
CVE-2024-47083 HIGH
Power Platform Terraform Provider <3.0.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 1,170
Exploit Likelihood Medium