BaseIncomplete

CWE-532Insertion of Sensitive Information into Log File

Category: data-exposure

Description

The product writes sensitive information to a log file.

Common consequences· 1

  • Confidentiality — Read Application Data
    Logging sensitive user data, full path names, or system information often provides attackers with an additional, less-protected path to acquiring the information.

Potential mitigations· 4

  • [Architecture and Design, Implementation]Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files.
  • [Distribution]Remove debug log files before deploying the application into production.
  • [Operation]Protect log files against unauthorized read/write.
  • [Implementation]Adjust configurations appropriately when software is transitioned from a debug state to production.

Related CAPEC attack patterns· 1

CAPEC-215

References

  1. https://cwe.mitre.org/data/definitions/532.html

Exploits (incoming)1

TypeTargetConfidenceTier
AttackPatternFuzzing for application mappingcapec-215100%live

Compliance frameworks addressing this (incoming)9

TypeTargetConfidenceTier
ComplianceControlowasp_llm_top10-llm02100%live
ComplianceControlcis_v8-3100%live
ComplianceControliso27701-a.7.2.2100%live
ComplianceControliso27701-a.7.4.1100%live
ComplianceControliso27701-a.7.2.1100%live
ComplianceControlgdpr-art5100%live
ComplianceControliso27701-a.7.5.1100%live
ComplianceControlai_act-art12100%live
ComplianceControlpci_dss_v4-r1095%live

(incoming)13

TypeTargetConfidenceTier
VulnerabilityCVE-2025-11008cve-2025-110080%live
VulnerabilityCVE-2025-22275cve-2025-222750%live
VulnerabilityMicrosoft Windows NTFS Information Disclosure Vulnerabilitycve-2025-249840%live
VulnerabilityCVE-2025-31479cve-2025-314790%live
VulnerabilityCVE-2025-63729cve-2025-637290%live
VulnerabilityCVE-2025-6391cve-2025-63910%live
VulnerabilityCVE-2026-22038cve-2026-220380%live
VulnerabilityCVE-2026-22778cve-2026-227780%live
VulnerabilityCVE-2026-25193cve-2026-251930%live
VulnerabilityCVE-2026-28923cve-2026-289230%live
VulnerabilityCVE-2026-43992cve-2026-439920%live
KEVEntrySamsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerabilitykev-cve-2023-214920%live
KEVEntryMicrosoft Windows NTFS Information Disclosure Vulnerabilitykev-cve-2025-249840%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Insertion of Sensitive Information into Externally-Accessible File or Directory
CWE
Insertion of Sensitive Information Into Debugging Code
CWE
Storage of Sensitive Data in a Mechanism without Access Control
CWE
Generation of Error Message Containing Sensitive Information
CWE
Cleartext Storage of Sensitive Information in Memory
CWE
Storage of File With Sensitive Data Under FTP Root
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.