Weaknesses of type CWE-532

852 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2022-44624MEDIUMIn JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special charactersEPSS 0.6%CVE-2023-5499HIGHShenzhen Reachfar v28 information exposureEPSS 0.6%CVE-2024-42349MEDIUMFOG has a Log Information DisclosureEPSS 0.6%CVE-2021-36278HIGHDell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local EPSS 0.6%CVE-2024-37283MEDIUMElastic Agent Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2022-3293LOWEmail addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 priEPSS 0.6%CVE-2024-0472LOWcode-projects Dormitory Management System modifyuser.php information disclosureEPSS 0.6%CVE-2024-33637HIGHWordPress Solid Affiliate plugin <= 1.9.1 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.6%CVE-2023-23591MEDIUMThe Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs EPSS 0.6%CVE-2024-28186HIGHSMTP Mail Credentials Disclosed in Error Log in freescoutEPSS 0.6%CVE-2023-46667HIGHFleet Server Insertion of Sensitive Information into Log FileEPSS 0.5%CVE-2022-49037MEDIUMInsertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allowEPSS 0.5%CVE-2024-32788MEDIUMWordPress FG Joomla to Wordpress plugin <= 4.20.2 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2020-5262HIGHGitHub personal access token leaking into temporary EasyBuild (debug) logsEPSS 0.5%CVE-2022-23506MEDIUMSpinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer buildsEPSS 0.5%CVE-2023-20885MEDIUMCF workflows leak credentials in system audit logsEPSS 0.5%CVE-2018-16859MEDIUMExecution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' paEPSS 0.5%CVE-2023-32478CRITICAL Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged maliEPSS 0.5%CVE-2021-3039LOWPrisma Cloud Compute: User role authorization secret for Console leaked through log file exportEPSS 0.5%CVE-2025-24556HIGHWordPress MooWoodle plugin <= 3.2.4 - Sensitive Data Exposure vulnerabilityEPSS 0.5%