CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2023-26207 LOW
Fortinet FortiOS <7.2.5 - Info Disclosure
CVSS 3.3
CVE-2023-2878 MEDIUM
Kubernetes secrets-store-csi-driver <1.3.3 - Info Disclosure
CVSS 6.5
CVE-2023-34097 HIGH
hoppscotch <2023.4.5 - Privilege Escalation
CVSS 7.8
CVE-2023-34223 MEDIUM
JetBrains TeamCity < 2023.05 - Sensitive Information Disclosure in Log Files
CVSS 4.3
CVE-2023-28351 LOW
Faronics Insight 10.0.19045 - Sensitive Information Exposure via Keystroke Logging
CVSS 3.3
CVE-2023-33001 HIGH
Jenkins HashiCorp Vault Plugin < 360.v0a_1c04cf807d - Credential Exposure in Build Logs via Durable Task Logging
CVSS 7.5
CVE-2023-2514 MEDIUM
Mattermost < 7.1.7 - Sensitive Information Disclosure in Application Logs
CVSS 6.7
CVE-2023-22447 LOW
Intel Open Cache Acceleration Software < 22.6.2 - Sensitive Information Disclosure via Log File Insertion
CVSS 2.0
CVE-2023-31413 LOW
Filebeat <= 7.17.9 and 8.6.2 - Sensitive Information Disclosure in HTTPJSON Input Debug Logs
CVSS 3.3
CVE-2023-21492 MEDIUM KEV
Samsung Android - Kernel Pointer Disclosure in Log File
CVSS 4.4
CVE-2023-31207 MEDIUM
Checkmk <=2.1.0p26-2.2.0b6 - Info Disclosure
CVSS 4.4
CVE-2023-1786 MEDIUM
Cloud-init <23.1.2 - Info Disclosure
CVSS 5.5
CVE-2023-31056 CRITICAL
CloverDX < 5.17.3 - Sensitive Information Disclosure in Audit Log
CVSS 9.1
CVE-2023-30618 LOW
kitchen-terraform 7.0.0 - Sensitive Information Exposure in Log File
CVSS 3.2
CVE-2023-30610 MEDIUM
aws-sigv4 0.55.0 - Sensitive Information Exposure via Debug Logging
CVSS 5.5
CVE-2023-29002 HIGH
Cilium 1.7.0-1.11.15 - Sensitive Information Exposure in Debug Logs
CVSS 7.2
CVE-2023-23591 MEDIUM
Terminalfour < 8.2.18.2.2 - Sensitive Information Exposure in Logback Debug Logs
CVSS 4.9
CVE-2023-1550 MEDIUM
NGINX Agent <2.23.3 - Info Disclosure
CVSS 5.5
CVE-2023-25721 MEDIUM
Veracode Scan Jenkins Plugin < 23.3.19.0 - Proxy Credential Exposure in Debug Logs
CVSS 6.5
CVE-2023-28630 MEDIUM
GoCD 20.5.0-23.1.0 - Database Credential Exposure via Backup Failure Alert
CVSS 4.2
CVE-2023-28443 MEDIUM
Directus < 9.23.3 - Unauthenticated Token Exposure via Log Output
CVSS 4.2
CVE-2023-28441 HIGH
smartCARS 3 <0.5.8 - Info Disclosure
CVSS 8.0
CVE-2023-20859 MEDIUM
Spring Vault 2.3.0-2.3.2 and 3.0.0-3.0.1 - Sensitive Information Disclosure in Log Files
CVSS 5.5
CVE-2023-25687 MEDIUM
IBM Security Guardium Key Lifecycle Manager 3.0-4.1.1 Sensitive Info Exposure via Log Files
CVSS 4.3
CVE-2023-22481 MEDIUM
FreshRSS 1.9.0-1.21.0 - Sensitive Information Disclosure in Greader API Logs
CVSS 4.0
Details
Vulnerabilities 1,137
Exploit Likelihood Medium