Windows Kernel Memory Information Disclosure Vulnerability
Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Fo
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may
A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently e
HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be
IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 throu
Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This is
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequo
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Se
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log
An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Saf
A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, ma
NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause
NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26,
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26,
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose i
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose inform
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclos
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe
Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sen
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C
Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, O
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat.
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols
A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to
"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obt
SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debuggi
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software cou
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC
Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log Fi
Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for i
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu
A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, aut
When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive inf
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started