CWE-532: CWE-532
Yearly Trend
Top Affected Vendors
All CWE-532 CVEs (207)
This vulnerability allows local users to gain sensitive information through insertion of sensitive data into log files in multiple Hitachi Virtual Sto...
Mar 25, 2024CVE-2021-32724 is a critical vulnerability in the check-spelling GitHub Action that allows attackers to steal GITHUB_TOKEN secrets via crafted pull re...
Sep 9, 2021This vulnerability in vLLM allows attackers to leak heap memory addresses by sending invalid images to the multimodal endpoint, which reduces ASLR ent...
Feb 2, 2026The CE21 Suite WordPress plugin exposes sensitive authentication credentials in log files, allowing unauthenticated attackers to steal login credentia...
Nov 4, 2025Brocade ASCG versions before 3.3.0 log JSON Web Tokens (JWT) in plain text within log files. Attackers with access to these logs can extract unencrypt...
Jul 17, 2025CVE-2024-52009 is a critical vulnerability in Atlantis that logs GitHub access tokens during rotation, exposing them to anyone with log read access. T...
Nov 8, 2024This vulnerability exposes user access tokens (JWTs) to the api.form.io domain when opening forms in Valtimo, allowing attackers to steal tokens and i...
May 14, 2024This vulnerability allows attackers to steal session IDs from Graylog DEBUG log files, enabling them to impersonate legitimate users and gain their ac...
Jul 31, 2021CVE-2023-36649 allows attackers to obtain JWT tokens from Grafana logs or Loki REST API in ProLion CryptoSpike 3.0.15P2. With these tokens, attackers ...
Dec 12, 2023Kibana 8.10.0 logs sensitive information like authentication credentials, cookies, and authorization headers in error logs when configured with JSON l...
Oct 26, 2023Dell PowerStore storage systems prior to version 3.5.0.1 write sensitive information to log files. A malicious high-privileged user could exploit this...
Jul 21, 2023This vulnerability in Weave GitOps allows authenticated remote attackers to view sensitive Kubernetes cluster configurations and service account token...
Jun 27, 2022Dell XtremIO version 6.4.0-22 logs sensitive information like credentials in log files. A low-privileged attacker with local access can read these log...
Jul 30, 2025This vulnerability allows authenticated remote attackers to access sensitive information from API endpoints or log files in Fortinet FortiAIOps. Attac...
Jul 9, 2024Dell EMC Data Protection Search and IDPA contain an information exposure vulnerability where sensitive user credentials are logged in plain text. A lo...
Aug 10, 2021Pimcore versions before 12.3.1 and 11.5.14 store sensitive information like database passwords and session cookies in the http_error_log file, which c...
Jan 15, 2026This vulnerability in Brocade SANnav management software exposes encrypted switch passwords in support save files from standby nodes. Attackers with a...
Apr 19, 2024This vulnerability in Gallagher Command Centre's Alarm Transmitter feature allows authenticated operators to view sensitive security information they ...
Dec 12, 2024CVE-2023-46672 is a Logstash vulnerability where sensitive information from the keystore can be exposed in JSON-formatted logs when referenced as vari...
Nov 15, 2023This vulnerability exposes agent and customer passwords in plain text within OTRS admin logs when specific authentication source configurations align ...
Aug 26, 2024Splunk Add-on Builder versions below 4.1.4 write sensitive information like credentials and API keys to internal log files. This vulnerability allows ...
Jan 30, 2024CVE-2021-21558 is an information disclosure vulnerability in Dell EMC NetWorker backup software where local administrators can read LDAP credentials f...
Jun 8, 2021AutoGPT versions before beta-v0.6.46 log API keys and authentication secrets in plaintext when using Stagehand integration blocks. This exposes sensit...
Feb 4, 2026CVE-2023-6746 is an information disclosure vulnerability in GitHub Enterprise Server where sensitive data is logged, potentially enabling man-in-the-m...
Dec 21, 2023Fleet Server versions 8.10.0 through 8.10.2 log agent enrollment tokens in plain text, allowing attackers who access logs to enroll unauthorized agent...
Oct 26, 2023Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 expose sensitive information in log files. Local users with specific privileges (ISI_PR...
Aug 16, 2021Dell Networking Switches running Enterprise SONiC OS versions before 4.4.1 and 4.2.3 have a vulnerability where sensitive information can be inserted ...
Jan 30, 2025This vulnerability in Kibana logs sensitive credentials like kibana_system user passwords, API keys, and end-user credentials when specific errors occ...
Dec 13, 2023Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x log sensitive information that could be accessed by local low-privileged users. This vulnerabil...
Mar 28, 2024CVE-2025-11547 is a privilege escalation vulnerability in AXIS Camera Station Pro that allows authenticated non-admin users to gain administrative pri...
Feb 10, 2026CVE-2025-66411 is an information disclosure vulnerability in Coder where sensitive values in Workspace Agent manifests were logged in plaintext withou...
Dec 3, 2025This vulnerability allows local users to extract authentication session tokens from cleartext log files in Vasion Print (formerly PrinterLogic) deploy...
Sep 19, 2025Dell PowerScale OneFS versions 9.1.0.x through 9.4.0.x log sensitive information (likely passwords) when users change passwords via the API. A local a...
Feb 1, 2023Dell VNX2 OE for File versions 8.1.21.266 and earlier contain a sensitive information disclosure vulnerability that allows local malicious users to re...
Jan 25, 2022Dell EMC Secure Connect Gateway (SCG) versions 5.00.00.10 and earlier contain a sensitive information disclosure vulnerability. A local malicious user...
Nov 20, 2021This CVE describes a logging vulnerability in Apple's iCloud Keychain where sensitive data (usernames and associated websites) was not properly redact...
May 12, 2025A vulnerability in kanidm-provision versions before 1.2.0 causes admin credentials to be leaked to system logs when using optional patches to provisio...
Mar 24, 2025PlaciPy placement management system logs sensitive data to console output without redaction in version 1.0.0. This allows attackers with access to con...
Feb 9, 2026RustFS versions alpha.13 through alpha.81 log sensitive AWS credentials (access keys, secret keys, session tokens) in plaintext at INFO level. This al...
Feb 3, 2026RustFS versions 1.0.0-alpha.1 through 1.0.0-alpha.79 log the shared HMAC secret when invalid RPC signatures are received. This exposes the secret to a...
Jan 16, 2026Apache Airflow versions before 3.1.6 expose proxy credentials in logs when connections contain proxy URLs with embedded authentication. This allows at...
Jan 16, 2026The Hummingbird Performance WordPress plugin exposes sensitive information including Cloudflare API credentials to unauthenticated attackers via the '...
Dec 18, 2025Docker Desktop diagnostics bundles inadvertently include expired Personal Access Tokens (PATs) in log output due to error object serialization issues....
Dec 9, 2025This vulnerability in Apache APISIX exposes basic authentication credentials (usernames and passwords) in plaintext within error logs when log levels ...
Oct 31, 2025The Quickcreator WordPress plugin exposes API keys through an accessible text file, allowing unauthenticated attackers to obtain credentials and perfo...
Oct 24, 2025OpenBao versions 2.2.0 to 2.4.1 have an audit log regression where raw HTTP bodies for certain endpoints aren't properly redacted. This leaks ACME ver...
Oct 22, 2025This vulnerability allows unauthenticated remote attackers to retrieve plaintext credentials from exposed log files in Ilevia EVE X1 Server. It enable...
Sep 16, 2025This vulnerability causes Checkmk to write remote site authentication secrets to log files accessible to administrators. Attackers with access to thes...
Apr 22, 2025This vulnerability in Checkmk monitoring software causes LDAP authentication credentials to be written to Apache error log files. Administrators with ...
Feb 19, 2025This vulnerability in the DualCube MooWoodle WordPress plugin allows attackers to retrieve sensitive data embedded in log files. It affects all versio...
Feb 3, 2025About CWE-532 (CWE-532)
Our database tracks 207 CVEs classified as CWE-532, with 12 rated critical and 75 rated high severity. The average CVSS score for CWE-532 vulnerabilities is 6.4.
External reference: View CWE-532 on MITRE CWE →
Monitor CWE-532 Vulnerabilities
Get alerted when new CWE-532 CVEs affect your infrastructure.
Start Monitoring Free