Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the
Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in
IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a loc
Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all vers
Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is
A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe ser
A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file,
An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the lo
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials f
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™
Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client befo
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated atta
An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific ca
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allo
A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orches
A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech su
Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitiv
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log f
IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read
Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/version
Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryable
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e
A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information in
An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that index
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not
APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_sh
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled lo
Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local us
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 an
GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a ta
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with l
IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a loca
Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log r
The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption
IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace l
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driv
A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext durin
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 an
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak
An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started