The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local a
A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records t
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy
Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.
Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.
Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensiti
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the
AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker
The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user
The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pa
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read
In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration
When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to at
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writin
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit
In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.251
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, whic
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose informati
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attacker
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitiv
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially s
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio
hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on t
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privilege
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able
unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-agains
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.
Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI ru
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) store
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be
fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to be
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 187 CVE records associated with CWE-532 in our database. Of these, 3 are critical severity, 40 are high severity, and 104 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started