CWE-778Base

Insufficient Logging

Draft in the CWE catalog · 28 CVEs mapped

28
CVEs mapped
4.3
Median CVSS
What it is

When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.

Recent examples
3.3cvss
CVE-2026-82863

CVE-2026-82863 - LOW Severity Vulnerability

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.

LOWno explanation yet
0%
epss
6.3cvss
CVE-2020-37268

CVE-2020-37268 - MEDIUM Severity Vulnerability

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining drops the record that the term was built under Unset Universe Checking, so the resulting constant carries no trace of the unsafe operation. A module implementation can therefore prove False using a universe inconsistency, expose it through an inlined parameter, and have Print Assumptions report the dependent proof as closed under the global context. Because Print Assumptions is the in-process audit used to confirm that a development rests on no unexpected assumptions, a dependency built this way passes that audit while proving arbitrary propositions. The standalone checker coqchk does reject the resulting compiled file. The project records this in dev/doc/critical-bugs.md under non-fixed bugs and rates the risk as moderate when coqchk is not used.

MEDIUMno explanation yet
0%
epss
5.4cvss
CVE-2025-62307

CVE-2025-62307 - MEDIUM Severity Vulnerability

HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-778
Abstraction
Base
Structure
Simple
Status
Draft
References (2)