An issue in iTop DualSafe Password Manager & Digital Vault prior to 1.4.24 allows a local malicious user to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.