CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2023-23505 LOW
iPadOS < 15.7.3 - Unprotected User Contact Data Exposure via Log File
CVSS 3.3
CVE-2023-0815 MEDIUM
OpenNMS Horizon < 31.0.4 and Meridian < 2023.1.0 - Sensitive Information Disclosure in Jetty Log Files
CVSS 6.8
CVE-2023-22362 HIGH
SUSHIRO App for Android <4.0.31-<2.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-21435 MEDIUM
Samsung Android - Sensitive Information Exposure in Fingerprint TA via Log
CVSS 4.4
CVE-2023-25163 MEDIUM
Argo CD >=2.6.0-rc1 <2.6.1 - Sensitive Information Disclosure in Error Messages
CVSS 6.3
CVE-2023-25164 HIGH
Tinacms 1.0.0-1.0.9 - Exposure of Sensitive Information via Environment Variable Leak
CVSS 8.6
CVE-2023-24827 MEDIUM
Syft v0.69.0-0.69.1 - Info Disclosure
CVSS 6.5
CVE-2023-22575 HIGH
Dell PowerScale OneFS 9.1.0.0-9.1.0.26 - Sensitive Information Disclosure in celog
CVSS 8.7
CVE-2023-22574 HIGH
Dell PowerScale OneFS 9.1.0.0-9.1.0.26 - Information Disclosure and Denial of Service via IPMI Module Log File
CVSS 8.1
CVE-2023-22573 HIGH
Dell PowerScale OneFS 9.1.0.0-9.1.0.26 - Sensitive Information Disclosure via Cloudpool Log File
CVSS 7.9
CVE-2023-22572 HIGH
Dell PowerScale OneFS 9.1.0.0-9.1.0.27 - Sensitive Information Exposure via Change Password API
CVSS 7.8
CVE-2023-22733 LOW
Shopware < 6.4.18.1 - Sensitive Information Disclosure in Log Module
CVSS 2.7
CVE-2022-35202 MEDIUM
Sitevision <10.3.1 - Info Disclosure
CVSS 5.1
CVE-2022-43937 MEDIUM
Brocade SANnav <2.3.0, 2.2.2a - Info Disclosure
CVSS 5.7
CVE-2022-43936 MEDIUM
Brocade SANnav <2.2.2 - Info Disclosure
CVSS 6.8
CVE-2022-43935 MEDIUM
Brocade SANnav <2.2.2 - Info Disclosure
CVSS 5.3
CVE-2022-43933 MEDIUM
Brocade SANnav <2.2.2 - Info Disclosure
CVSS 4.4
CVE-2022-49037 MEDIUM
Synology Drive Client <3.3.0-15082 - Info Disclosure
CVSS 6.5
CVE-2022-26322 MEDIUM
OpenText Identity Manager <1.1.2.0200 - Info Disclosure
CVSS 4.9
CVE-2022-25477 MEDIUM
Realtek RtsPer < 10.0.22000.21355 and RtsUer < 10.0.22000.31274 - Kernel Address Leak via Driver Logs
CVSS 5.5
CVE-2022-44587 MEDIUM
Melapress WP 2fa < 2.6.4 - Log Information Exposure
CVSS 5.3
CVE-2022-36407 CRITICAL
Hitachi Virtual Storage Platform - Info Disclosure
CVSS 9.9
CVE-2022-46647 LOW
Intel Unison Software < 20.14.5683.0 - Authenticated Information Disclosure via Log File Insertion
CVSS 2.2
CVE-2022-27599 MEDIUM
QVR Pro Client < 2.3.0.0420 - Authenticated Sensitive Information Disclosure via Log File
CVSS 6.7
CVE-2022-0010 HIGH
ABB QCS 800xA < 6.1SP2, QCS AC450 < 5.1SP2, Platform Engineering Tools < 2.3.0 - Sensitive Information Disclosure
CVSS 7.8
Details
Vulnerabilities 1,137
Exploit Likelihood Medium