Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP reques
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications.
The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file downl
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administra
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.
ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effe
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returne
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string lar
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The we
In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive t
Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, a
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all vers
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage S
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module
In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with d
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scrip
Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwo
An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a sce
Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linu
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained sp
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the us
IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could b
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable gui
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by th
Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive informati
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6
An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allo
Windows Desired State Configuration (DSC) Information Disclosure Vulnerability
A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated,
In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering.
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud
A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Wi
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow
The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensiti
Azure SDK for .NET Information Disclosure Vulnerability
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started