An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a W
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively us
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single s
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows re
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A
An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. Th
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in cel
Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tina
An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstanc
Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to ret
A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in pl
An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into th
An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterpris
smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will hav
An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error
An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloud
Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in chan
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering
hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed i
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a crede
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) cred
A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a parti
Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Wind
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensiti
Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to
Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensi
Headscale through 0.22.3 writes bearer tokens to info-level logs.
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Ciliu
An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Co
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability
Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon c
The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0
An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents
An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or
An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR leve
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initializ
An insertion of sensitive information into Log file vulnerability has been reported to affect product. If exploited, the
syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and
IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files
Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with prox
Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attack
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started