CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2020-13830 HIGH
Google Android - Log Information Exposure
CVSS 7.5
CVE-2020-11094 MEDIUM
October CMS debugbar <3.1.0 - Info Disclosure
CVSS 6.1
CVE-2020-3281 HIGH
Cisco Digital Network Architecture Center < 1.3.3.3 - Authenticated Sensitive Information Exposure in Audit Logs
CVSS 8.8
CVE-2020-7654 HIGH
Snyk Broker < 4.73.1 - Sensitive Information Exposure in Debug Logs
CVSS 7.5
CVE-2020-2004 MEDIUM
GlobalProtect 5.0.0-5.0.8 and 5.1.0-5.1.1 - Sensitive Information Disclosure in PanGPS.log
CVSS 6.8
CVE-2020-11932 LOW
Subiquity < 20.05.2 - Sensitive Information Exposure via Log File
CVSS 2.3
CVE-2020-1698 MEDIUM
Keycloak < 9.0.0 - Password Exposure via HttpMethod Exception Logging
CVSS 5.0
CVE-2020-10712 HIGH
OpenShift Container Platform <4.1 - Info Disclosure
CVSS 7.0
CVE-2020-11968 HIGH
IQrouter Firmware < 3.3.1 - Unauthenticated Sensitive Information Exposure via Web Panel Log Access
CVSS 7.5
CVE-2020-6224 MEDIUM
SAP NetWeaver AS Java - Info Disclosure
CVSS 6.2
CVE-2020-1624 MEDIUM
Junos OS Evolved < 19.1r1 - Authenticated Sensitive Information Exposure via Raw objmon Configuration Files
CVSS 5.5
CVE-2020-1623 MEDIUM
Junos OS Evolved < 19.2r1 - Authenticated Sensitive Information Exposure via ev.ops Configuration File
CVSS 5.5
CVE-2020-1622 MEDIUM
Junos OS Evolved < 19.1R1 - Authenticated Sensitive Information Exposure via EvoSharedObjStore
CVSS 5.5
CVE-2020-1621 MEDIUM
Junos OS Evolved < 19.3r1 - Authenticated Password Hash Exposure via Configd Traces
CVSS 5.5
CVE-2020-1620 MEDIUM
Junos OS Evolved < 19.3R1 - Authenticated Password Hash Exposure via Configd Streamer Log
CVSS 5.5
CVE-2020-1987 LOW
GlobalProtect 5.0-5.0.8 - Authenticated VPN Cookie Exposure via Troubleshooting Log Level
CVSS 3.9
CVE-2020-11605 HIGH
Android O(8.x), P(9.0), Q(10.0) - Sensitive Information Exposure in NFC Logs
CVSS 7.5
CVE-2020-7599 MEDIUM
com.gradle.plugin-publish < 0.11.0 - Sensitive Information Exposure via Log File
CVSS 6.5
CVE-2020-5262 HIGH
EasyBuild < 4.1.2 - Sensitive Information Exposure via Debug Log Files
CVSS 7.7
CVE-2020-1753 MEDIUM
Ansible Engine <2.7.17, <2.8.11, <2.9.7 - Info Disclosure
CVSS 5.0
CVE-2020-4083 MEDIUM
HCL Connections 6.5 - Sensitive Information Disclosure via Trace Logs
CVSS 5.5
CVE-2020-5400 MEDIUM
Cloud Foundry CAPI < 1.91.0 - Insufficiently Protected Credentials in Background Job Logs
CVSS 6.5
CVE-2020-0018 MEDIUM
Android 8.0-10 - Authenticated User Input Disclosure via InputDispatcher Log
CVSS 4.4
CVE-2020-1942 HIGH
Apache NiFi 0.0.1-1.11.0 - Sensitive Information Disclosure in Flow Fingerprint Logs
CVSS 7.5
CVE-2020-1928 MEDIUM
Apache NiFi 1.10.0 - Sensitive Information Disclosure in Parameter Parser
CVSS 5.3
Details
Vulnerabilities 1,137
Exploit Likelihood Medium