CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2021-24024 MEDIUM
FortiADC < 5.3.7 and FortiADCManager < 5.3.0 - Authenticated Sensitive Information Disclosure in Log Files
CVSS 4.3
CVE-2021-23924 HIGH
Devolutions Server < 2020.3 - Sensitive Information Exposure in Diagnostic Files
CVSS 7.5
CVE-2021-3447 MEDIUM
Red Hat Ansible < 1.2.2 and Ansible Tower < 3.8.2 - Sensitive Information Exposure in Log Files
CVSS 5.5
CVE-2021-22184 MEDIUM
GitLab 12.8.0-13.6.5 - Sensitive Information Disclosure in Server Logs
CVSS 6.2
CVE-2021-25350 LOW
Samsung Account <12.1.1.3 - Info Disclosure
CVSS 2.0
CVE-2021-1442 HIGH
Cisco IOS XE - Authenticated Privilege Escalation via PnP Diagnostic Command
CVSS 7.8
CVE-2021-22310 MEDIUM
Huawei NIP6300/NIP6600/Secospace USG6300/USG6500/USG6600/USG9500 Firmware - Information Leakage via Log File
CVSS 4.4
CVE-2021-3167 MEDIUM
Cloudera Data Engineering 1.3.0 - Sensitive Information Exposure in Log Files
CVSS 6.5
CVE-2021-3034 MEDIUM
Cortex XSOAR <5.5.0-6.0.1 - Info Disclosure
CVSS 5.1
CVE-2021-21361 MEDIUM
gradle-vagrant-plugin < 3.0.0 - Sensitive Information Disclosure via Environment Variable Logging
CVSS 5.3
CVE-2021-25284 MEDIUM
SaltStack Salt <3002.5 - Info Disclosure
CVSS 4.4
CVE-2021-25688 MEDIUM
Teradici PCoIP Agents < 20.10.0 (Windows) and < 21.01.0 (Linux) - Sensitive Information Exposure via Log File
CVSS 5.5
CVE-2021-22133 LOW
Elastic APM Agent for Go < 1.11.0 - Sensitive Information Exposure via Panic Log
CVSS 2.4
CVE-2021-20359 MEDIUM
IBM Cloud Pak for Automation <20.0.3 - Info Disclosure
CVSS 6.5
CVE-2021-21722 MEDIUM
ZTE ZXV10 B860A Firmware V2.1-T_V0032.1.1.04_jiangsuTelecom - Sensitive Information Exposure via Log File
CVSS 4.4
CVE-2021-1226 MEDIUM
Cisco Unified Communications - Info Disclosure
CVSS 4.3
CVE-2021-3032 MEDIUM
Palo Alto Networks PAN-OS <8.1 - Info Disclosure
CVSS 4.4
CVE-2020-36876 HIGH
ReQuest Serious Play F3 Media Server <7.0.3.4968 - Info Disclosure
CVE-2020-24804 MEDIUM
cms-dev/cms v1.4.rc1 - Plaintext Password Exposure in AddAdmin.py
CVSS 6.5
CVE-2020-10052 MEDIUM
SIMATIC RTLS Locating Manager < 2.12 - Sensitive Information Disclosure in Log Files
CVSS 5.5
CVE-2020-21933 HIGH
Motorola CX2 Firmware - Sensitive Information Exposure in Log Files
CVSS 7.5
CVE-2020-23284 HIGH
MV IDCE 1.0 - Unauthenticated Sensitive Information Disclosure via ASPX Page URL Manipulation
CVSS 7.5
CVE-2020-24038 MEDIUM
myFax 229 - Sensitive Information Exposure in Export Log Module
CVSS 6.5
CVE-2020-15380 HIGH
Brocade SANnav <2.1.1 - Info Disclosure
CVSS 7.5
CVE-2020-7021 MEDIUM
Elasticsearch < 6.8.14 - Sensitive Information Disclosure in Audit Logs
CVSS 4.9
Details
Vulnerabilities 1,137
Exploit Likelihood Medium