OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials w
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s us
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /ho
On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys ar
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2
The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sens
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive informati
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when log
Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.
Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply
Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENO
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block comman
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated at
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure paramete
On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-
IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be r
IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token tha
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k
IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file.
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may l
IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-m
Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden whe
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, c
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an acco
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes
All versions of unity-scope-gdrive logs search terms to syslog.
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were l
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Inform
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive va
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnera
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to al
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started