CWE · MITRE source
CWE-532Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): CAPEC 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A09:2025 Security Logging and Alerting Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (9)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
AU-1 | Policy and Procedures | AU | Procedures mandate excluding sensitive data from logs to prevent unauthorized exposure via audit records. |
AU-13 | Monitoring for Information Disclosure | AU | Identifies insertion of sensitive data into logs, allowing detection of unauthorized disclosure. |
AU-16 | Cross-organizational Audit Logging | AU | Cross-organizational coordination enables agreement on what data to include in audit logs, directly reducing insertion of sensitive information. |
CM-13 | Data Action Mapping | CM | Identifying logging as a data action allows prevention of sensitive information being inserted into log files. |
IR-9 | Information Spillage Response | IR | The process of identifying and eradicating spilled information applies directly to sensitive data inserted into log files. |
PT-7 | Specific Categories of Personally Identifiable Information | PT | Specific processing rules for sensitive PII categories commonly include restrictions on logging, making insertion of such data into log files less likely. |
RA-8 | Privacy Impact Assessments | RA | PIAs detect planned or existing logging of PII and require removal or protection, preventing insertion of sensitive information into logs. |
SC-38 | Operations Security | SC | Limits insertion of sensitive operational details into logs by treating such data as key information requiring protection. |
SI-15 | Information Output Filtering | SI | Checking application output against expected content catches insertion of sensitive values into log streams or files. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2018-11716 UPD | 8.4 | 9.8 | 0.1429 | 2018-07-16 |
CVE-2020-35234 UPD | 8.2 | 7.5 | 0.6460 | 2020-12-14 |
CVE-2018-11717 UPD | 8.1 | 9.8 | 0.0858 | 2018-07-16 |
CVE-2023-43261 UPD | 8.1 | 7.5 | 0.5934 | 2023-10-04 |
CVE-2024-20440 UPD | 7.9 | 7.5 | 0.5190 | 2024-09-04 |
CVE-2017-7550 UPD | 7.8 | 9.8 | 0.0356 | 2017-11-21 |
CVE-2018-17922 UPD | 7.8 | 9.8 | 0.0324 | 2018-11-02 |
CVE-2019-3888 UPD | 7.8 | 9.8 | 0.0303 | 2019-06-12 |
CVE-2026-22778 UPD | 7.8 | 9.8 | 0.0372 | 2026-02-02 |
CVE-2017-7214 UPD | 7.7 | 9.8 | 0.0230 | 2017-03-21 |
CVE-2017-8074 UPD | 7.7 | 9.8 | 0.0194 | 2017-04-23 |
CVE-2017-6165 UPD | 7.7 | 9.8 | 0.0192 | 2017-10-20 |
CVE-2018-1000060 UPD | 7.7 | 9.8 | 0.0236 | 2018-02-09 |
CVE-2016-0898 UPD | 7.7 | 10.0 | 0.0141 | 2018-03-29 |
CVE-2018-16049 UPD | 7.7 | 9.8 | 0.0215 | 2018-10-03 |
CVE-2019-4008 UPD | 7.7 | 9.8 | 0.0227 | 2019-02-07 |
CVE-2019-7612 UPD | 7.7 | 9.8 | 0.0241 | 2019-03-25 |
CVE-2017-8075 UPD | 7.6 | 9.8 | 0.0179 | 2017-04-23 |
CVE-2017-4955 UPD | 7.6 | 9.8 | 0.0141 | 2017-06-13 |
CVE-2017-9615 UPD | 7.6 | 9.8 | 0.0140 | 2017-06-26 |
CVE-2017-6709 UPD | 7.6 | 9.8 | 0.0129 | 2017-07-06 |
CVE-2017-15366 UPD | 7.6 | 9.8 | 0.0141 | 2017-10-26 |
CVE-2017-1000171 UPD | 7.6 | 9.8 | 0.0138 | 2017-11-03 |
CVE-2018-1000123 UPD | 7.6 | 9.8 | 0.0143 | 2018-03-13 |
CVE-2018-11320 UPD | 7.6 | 9.8 | 0.0138 | 2018-05-21 |