System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This lead
wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages t
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da
PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9,
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup lo
Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service
A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.
Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Stor
Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access toke
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs
Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve
Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet Forti
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the B
Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature cou
A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Au
In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.
Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations reg
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vuln
Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allow
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines ca
The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containin
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise Manage
Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue
Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is st
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged u
Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a t
Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid
spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be
Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from
apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in l
Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affec
A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for c
Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and e
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive inf
Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior
Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Infor
AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address wi
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens duri
AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before
FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free
An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive inf
In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when
A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability c
The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication ses
The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retr
Under certain circumstances unnecessary user details are provided within system logs
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started