CWE-532
Insertion of Sensitive Info into Log File
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 10 of 10- CVE-2025-46313Medium· 5.5EPSS 0%10 h ago
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2026-9751Medium· 5.5EPSS 0%11 h ago
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
- CVE-2023-21492Medium· 4.4KEVEPSS 0%15 h ago
Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
- CVE-2025-24984Medium· 4.6KEVEPSS 4%15 h ago
Microsoft Windows NTFS Information Disclosure Vulnerability
- CVE-2021-39913Medium· 4.4EPSS 0%17 h ago
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local fi
- CVE-2026-0267—EPSS 0%1 d ago
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is kno
- CVE-2026-9735Medium· 5.5EPSS 0%2 d ago
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redac
- CVE-2025-31514Low· 2.7EPSS 0%3 d ago
A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3
- CVE-2026-45581Medium· 5.5EPSS 0%3 d ago
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
maven - CVE-2026-49200Critical· 9.8EPSS 0%4 d ago
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.