Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privi
When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.
IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local priv
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma
In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log inform
Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Ro
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some c
In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log
In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log
Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log
IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive informa
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated us
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_
GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environm
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configu
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application per
In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the
Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found
FreshRSS is a self-hosted RSS feed aggregator. When using the greader API, the provided password is logged in clear in `
Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is imprope
A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging object
An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Dat
An issue was discovered in Plixer Scrutinizer before 19.3.1. It exposes debug logs to unauthenticated users at the /debu
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Montere
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or P
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with t
An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Big Sur
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords
Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform co
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module
Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for
Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physica
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 an
Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to poten
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application err
Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 2
A vulnerability, which was classified as problematic, has been found in China Unicom TEWA-800G 4.16L.04_CT2015_Yueme. Af
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information sto
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertio
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started