CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2023-6064 HIGH
PayHere Payment Gateway <2.2.12 - Info Disclosure
CVSS 7.5
CVE-2023-6802 HIGH
GitHub Enterprise Server >=3.8.0 <3.8.12 - Sensitive Information Disclosure in Audit Log
CVSS 7.2
CVE-2023-6746 HIGH
GitHub Enterprise Server 3.7.0-3.7.18 - Sensitive Information Insertion into Log File
CVSS 8.1
CVE-2023-1904 MEDIUM
Octopus Server 2022.1.2121-2023.1.11942 - Sensitive Information Disclosure in Log Files
CVSS 4.2
CVE-2023-46675 HIGH
Elastic Kibana <8.11.2 - Info Disclosure
CVSS 8.0
CVE-2023-46671 HIGH
Kibana 8.0.0-8.11.0 - Sensitive Information Disclosure in Error Logs
CVSS 8.0
CVE-2023-6687 MEDIUM
Elastic Agent 7.0.0-7.17.16 - Sensitive Information Disclosure in Log Files
CVSS 6.8
CVE-2023-49922 MEDIUM
Elastic Beats 7.0.0-7.17.15 and 8.0.0-8.11.2 - Sensitive Information Disclosure in Log Files
CVSS 6.8
CVE-2023-49923 MEDIUM
Elastic Enterprise Search 7.0.0-7.17.16 - Sensitive Information Disclosure in App Search Documents API Logs
CVSS 6.8
CVE-2023-36649 CRITICAL
ProLion CryptoSpike 3.0.15P2 - Info Disclosure
CVSS 9.1
CVE-2023-6460 MEDIUM
nodejs-firestore <6.1.0 - Info Disclosure
CVSS 4.0
CVE-2023-6287 LOW
Tribe29 Checkmk Appliance <1.6.8 - Info Disclosure
CVSS 3.3
CVE-2023-48708 MEDIUM
CodeIgniter Shield <1.0.0-beta.8 - Info Disclosure
CVSS 5.0
CVE-2023-4677 HIGH
Pandora FMS <= 772 - Unauthenticated Administrator Session ID Exposure via Cron Log Backup Files
CVSS 7.0
CVE-2023-25682 MEDIUM
IBM Sterling B2B Integrator 6.0.0.0-6.0.3.8 and 6.1.0.0-6.1.2.1 - Sensitive Information Disclosure in Log Files
CVSS 6.2
CVE-2023-46672 HIGH
Logstash 8.10.0-8.11.0 - Sensitive Information Disclosure in JSON Logs
CVSS 8.4
CVE-2023-32283 MEDIUM
Intel On Demand - Sensitive Information Insertion into Log File
CVSS 5.5
CVE-2023-45585 LOW
FortiSIEM <=7.0.0 - Authenticated Sensitive Information Disclosure in Debug Log Files
CVSS 2.3
CVE-2023-47390 HIGH
Headscale < 0.22.3 - Sensitive Information Exposure via Log File
CVSS 7.5
CVE-2023-0436 MEDIUM
MongoDB Atlas Kubernetes Operator 1.5.0-1.7.0 - Sensitive Information Exposure in DEBUG Logs
CVSS 4.5
CVE-2023-46255 MEDIUM
SpiceDB <1.27.0-rc1 - Info Disclosure
CVSS 4.2
CVE-2023-21387 MEDIUM
Android < 14.0 - Local Information Disclosure via User Backup Manager Log
CVSS 4.4
CVE-2023-46215 HIGH
Apache Airflow <2.6.3, <3.4.0 - Info Disclosure
CVSS 7.5
CVE-2023-31417 MEDIUM
Elasticsearch 7.0.0-7.17.12 - Sensitive Information Exposure in Audit Logs via Deprecated API URIs
CVSS 4.1
CVE-2023-31422 CRITICAL
Elastic Kibana <8.10.1 - Info Disclosure
CVSS 9.0
Details
Vulnerabilities 1,170
Exploit Likelihood Medium