An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block C
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an
IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The kernel logging feature
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning lev
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prio
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is
In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when
Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credenti
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files.
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets
Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and se
In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lea
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The C
IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inc
A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop A
In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead t
A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system p
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authen
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due t
A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 ver
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUS
GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read the
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms v
An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local
Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or re
In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can acc
An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs dri
An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log with
An information exposure through log file vulnerability where an administrator's password or other sensitive information
An information exposure through log file vulnerability exists where the password for the configured system proxy server
IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one wa
Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSi
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials throug
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service acc
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attack
In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentic
In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, an
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during au
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authenti
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started