In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for lo
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context valu
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log
CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret
Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in
Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the l
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credent
react-native-mmkv is a library that allows easy use of MMKV inside React Native applications. Before version 2.11.0, the
Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Releas
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to
The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that o
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application
IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where confi
In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applica
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to view
A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM
Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can exp
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed informati
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log f
Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server wil
When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will b
Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are no
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumsta
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 pr
Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerabi
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 pr
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affe
A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, m
Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2
The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affect
Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <
Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL d
Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly r
An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to
Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs t
The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthK
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started