CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2024-41129 MEDIUM
ops 2.0.0-2.14.9 - Sensitive Information Disclosure in Log Files via CLI Arguments
CVSS 4.4
CVE-2024-0006 MEDIUM
Yugabyte Platform - Info Disclosure
CVE-2024-40636 MEDIUM
Steeltoe.Discovery.Eureka < 3.2.8 - Sensitive Information Exposure in Log Files via Eureka Server Service URLs
CVSS 5.3
CVE-2024-39532 MEDIUM
Junos OS/Junos OS Evolved Sensitive Information Disclosure via Log File
CVSS 6.3
CVE-2024-37270 MEDIUM
TrustedLogin <1.1.1 - Info Disclosure
CVSS 5.3
CVE-2024-37205 MEDIUM
SERVIT Software Solutions - Info Disclosure
CVSS 5.3
CVE-2024-27784 HIGH
Fortinet FortiAIOps <2.0.0 - Info Disclosure
CVSS 8.8
CVE-2024-40598 MEDIUM
MediaWiki <1.42.1 - Info Disclosure
CVSS 4.3
CVE-2024-40596 MEDIUM
MediaWiki <1.42.1 - Info Disclosure
CVSS 4.3
CVE-2024-32757 MEDIUM
American Dynamics Illustra Essentials Gen 4 < Illustra.Ess4.01.02.10.5982 - Sensitive Information Exposure in Log Files
CVSS 6.8
CVE-2024-22276 MEDIUM
VMware Cloud Director - Info Disclosure
CVSS 5.3
CVE-2024-39460 MEDIUM
Jenkins Bitbucket Branch Source Plugin <= 886.v44cf5e4ecec5 - Sensitive Information Exposure in Build Log
CVSS 4.3
CVE-2024-28830 LOW
Checkmk <2.3.0p7, <2.2.0p28, <2.1.0p45, <=2.0.0p39 - Sensitive Information Disclosure in Audit Log Files
CVSS 2.7
CVE-2024-29177 LOW
Dell PowerProtect DD <8.0 - Info Disclosure
CVSS 2.7
CVE-2024-29954 MEDIUM
Brocade Fabric OS <9.2.1-8.2.3e - Info Disclosure
CVSS 5.9
CVE-2024-6060 CRITICAL
Phloc Webscopes 7.0.0 - Info Disclosure
CVE-2024-6104 MEDIUM
go-retryablehttp < 0.7.7 - Sensitive Information Disclosure via Log File
CVSS 6.0
CVE-2024-38460 MEDIUM
SonarQube <10.4, 9.9.4 - Info Disclosure
CVSS 4.9
CVE-2024-27157 MEDIUM
Toshiba Tec e-Studio MFP - Clear-Text Session Information Disclosure
CVSS 6.8
CVE-2024-27156 MEDIUM
Toshiba Tec e-Studio MFP - Sensitive Information Exposure via Clear-Text Session Cookie Logging
CVSS 6.8
CVE-2024-27154 MEDIUM
Toshiba Tec e-Studio MFP - Clear-Text Password Exposure in Log Files
CVSS 6.2
CVE-2024-5908 HIGH
GlobalProtect 5.1-5.1.11 - Sensitive Information Exposure in Application Logs
CVSS 7.5
CVE-2024-5557 MEDIUM
Schneider Electric SpaceLogic AS-B and AS-P Firmware < 6.0.1 - Sensitive Information Exposure via Log File
CVSS 4.5
CVE-2024-32811 MEDIUM
Octolize USPS Shipping <1.9.4 - Info Disclosure
CVSS 5.3
CVE-2024-0912 MEDIUM
Johnson Controls Software House CCURE 9000 SiteServer - Sensitive Information Disclosure in IIS Logs
CVSS 4.2
Details
Vulnerabilities 1,170
Exploit Likelihood Medium