MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able
Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an
Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, t
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerabilit
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy o
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.
Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS.
An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScri
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi
A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handl
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitac
IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0
An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused
The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackS
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature t
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged
Tanium addressed an information disclosure vulnerability in Threat Response.
In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users log
Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingSer
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This i
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug
IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores poten
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 1
Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the option
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert
Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is suppl
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log f
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) ,
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of se
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptograph
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs u
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started