CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2022-23715 MEDIUM
Elastic Cloud Enterprise < 3.4.0 - Sensitive Information Disclosure in Logs via PATCH APIs
CVSS 6.5
CVE-2022-29550 MEDIUM
Qualys Cloud Agent 4.8.0-49 - Sensitive Information Disclosure in Scan Log
CVSS 5.5
CVE-2022-38149 HIGH
HashiCorp Consul Template <0.27.2, 0.28.2, 0.29.1 - Info Disclosure
CVSS 7.5
CVE-2022-20278 MEDIUM
Android 13 - Sensitive Information Disclosure via Insufficient Log Filtering
CVSS 5.5
CVE-2022-31674 MEDIUM
VMware vRealize Operations 8.0.0-8.6.4 - Information Disclosure via Log File Access
CVSS 4.3
CVE-2022-38133 LOW
JetBrains TeamCity <2022.04.3 - Info Disclosure
CVSS 3.2
CVE-2022-29071 MEDIUM
Arista CloudVision Portal - Info Disclosure
CVSS 4.0
CVE-2022-31119 LOW
Nextcloud Mail <1.12.1 - Info Disclosure
CVSS 3.1
CVE-2022-31186 LOW
NextAuth.js <4.10.2, <3.29.9 - Info Disclosure
CVSS 3.3
CVE-2022-34570 HIGH
WAVLINK WN579 X3 M79X3.V5030.191012 - Information Disclosure via messages.txt Page
CVSS 7.5
CVE-2022-32556 HIGH
Couchbase Server 3.0.0-7.1.1 - Sensitive Information Disclosure via Log File
CVSS 7.5
CVE-2022-36321 MEDIUM
JetBrains TeamCity <2022.04.2 - Info Disclosure
CVSS 4.1
CVE-2022-2394 MEDIUM
Puppet Bolt <3.24.0 - Info Disclosure
CVSS 4.1
CVE-2022-23141 HIGH
ZTE ZXMP M721 Firmware - Sensitive Information Exposure via Serial Port Authentication Bypass
CVSS 7.5
CVE-2022-34826 MEDIUM
Couchbase Server 7.1.x - Sensitive Information Exposure via Log File
CVSS 5.9
CVE-2022-33911 MEDIUM
Couchbase Server <7.0.4 - Info Disclosure
CVSS 5.3
CVE-2022-33697 LOW
ImsCore <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 3.3
CVE-2022-33693 LOW
CID Manager <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 2.0
CVE-2022-33688 LOW
SecTelephonyProvider <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 3.3
CVE-2022-33687 LOW
telephony-common.jar <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 3.3
CVE-2022-27549 MEDIUM
HCL Launch - Sensitive Information Disclosure via Plain Text Log Storage
CVSS 4.0
CVE-2022-20768 MEDIUM
Cisco TelePresence CE/RoomOS - Info Disclosure
CVSS 4.9
CVE-2022-33737 HIGH
OpenVPN Access Server <2.11.0 - Info Disclosure
CVSS 7.5
CVE-2022-31098 CRITICAL
Weave GitOps < 0.8.1 - Sensitive Information Exposure in Log Files
CVSS 9.0
CVE-2022-20651 MEDIUM
Cisco ASDM 7.15.1-7.17.1 Authenticated Sensitive Information Disclosure
CVSS 5.5
Details
Vulnerabilities 1,137
Exploit Likelihood Medium