CWE-532
Insertion of Sensitive Information into Log File
About
The product writes sensitive information to a log file.
Common consequences
- Confidentiality → Read Application Data
Mitigations
- Architecture and Design, Implementation: Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files.
- Distribution: Remove debug log files before deploying the application into production.
- Operation: Protect log files against unauthorized read/write.
- Implementation: Adjust configurations appropriately when software is transitioned from a debug state to production.
CVEs with this weakness
Frequently asked questions
What is CWE-532?
The product writes sensitive information to a log file. Common consequences Confidentiality → Read Application Data Mitigations Architecture and Design, Implementation: Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files. Distribution: Remove debug log files before deploying the application into production.
How likely is CWE-532 to be exploited?
MITRE rates the likelihood of exploit for CWE-532 as medium.
How many CVEs does Rainforest track for CWE-532?
Rainforest Labs currently tracks 2 published CVEs mapped to CWE-532. They are listed on this page.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
