CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2024-7421 MEDIUM
Devolutions Remote Desktop Manager < 2024.3.10 - Local Credential Exposure via WinSCP Command-Line Arguments
CVSS 5.5
CVE-2024-43990 MEDIUM
StylemixThemes Masterstudy LMS Starter - Info Disclosure
CVSS 5.3
CVE-2024-44166 MEDIUM
macOS < 13.7, < 14.7, < 15 - Unprotected User Data Exposure via Log File Insertion
CVSS 5.5
CVE-2024-40791 LOW
macOS Ventura <13.7 - Info Disclosure
CVSS 3.3
CVE-2024-8775 MEDIUM
ansible-core >=2.17.0b1 <2.17.6 - Sensitive Information Exposure in Log Files via Vault Variable Handling
CVSS 5.5
CVE-2024-4472 MEDIUM
GitLab CE/EE <17.1.7-17.2.5-17.3.2 - Info Disclosure
CVSS 4.0
CVE-2024-43781 MEDIUM
SINUMERIK 828D/840D sl V4 < V4.95 SP3, ONE < V6.23/6.15 SP4 - Authenticated Sensitive Information Disclosure
CVSS 5.5
CVE-2024-42344 MEDIUM
SINEMA Remote Connect Client < 3.2 SP2 - Sensitive Information Disclosure in Log File
CVSS 4.4
CVE-2024-20440 HIGH
Cisco Smart Licensing Utility - Info Disclosure
CVSS 7.5
CVE-2024-8365 MEDIUM
HashiCorp Vault < 1.16.9, < 1.17.5 - Sensitive Information Disclosure in Audit Logs
CVSS 6.2
CVE-2024-43444 HIGH
OTRS <7.0.50,8.0.X,2023.X,2024.5.X - Info Disclosure
CVSS 8.2
CVE-2024-42056 MEDIUM
Retool 3.18.1-3.40.0 - Authenticated Credential Exposure via Resources Endpoint
CVSS 6.5
CVE-2024-6451 HIGH
AI Engine < 2.4.3 - Authenticated Remote Code Execution via Log Poisoning
CVSS 7.2
CVE-2024-41719 MEDIUM
BIG-IP Next Central Manager 20.1.0-20.2.0 - Sensitive Information Disclosure in QKView Logs
CVSS 4.2
CVE-2024-41978 MEDIUM
Siemens SCALANCE and RUGGEDCOM Firmware < 8.1 - Authenticated Sensitive Information Exposure in Log Files
CVSS 6.5
CVE-2024-37930 MEDIUM
ThemeSphere SmartMag < 10.1.0 - Sensitive Data Exposure via Log File Insertion
CVSS 5.3
CVE-2024-37283 MEDIUM
Elastic Agent 8.6.0-8.14.2 - Sensitive Information Disclosure in Debug Logs
CVSS 6.5
CVE-2024-40096 LOW
com.cascadialabs.who 15.0 - Info Disclosure
CVSS 3.3
CVE-2024-37286 MEDIUM
APM Server < 8.14.0 - Sensitive Information Disclosure in Error Logs
CVSS 5.7
CVE-2024-38321 MEDIUM
IBM Business Automation Workflow <24.0.0 - Info Disclosure
CVSS 5.3
CVE-2024-42349 MEDIUM
Fogproject < 1.5.10.47 - Log Information Exposure
CVSS 5.3
CVE-2024-6687 MEDIUM
CTT Expresso para WooCommerce <3.2.12 - Info Disclosure
CVSS 5.3
CVE-2024-6977 MEDIUM
Cato Networks SDP Client < 5.10.34 - Sensitive Information Insertion into Log File
CVSS 6.5
CVE-2024-41178 HIGH
Apache Arrow Rust Object Store < 0.10.1 - Sensitive Information Exposure in Logs via AWS WebIdentityToken
CVSS 7.5
CVE-2024-41824 MEDIUM
JetBrains TeamCity < 2024.07 - Sensitive Information Disclosure in Build Log
CVSS 6.4
Details
Vulnerabilities 1,170
Exploit Likelihood Medium