Weaknesses of type CWE-532

852 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2018-16889MEDIUMCeph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in lEPSS 0.5%CVE-2026-22782LOWRustFS RPC signature verification logs shared secretEPSS 0.5%CVE-2022-43887MEDIUMIBM Cognos Analytics information disclosureEPSS 0.5%CVE-2023-38732MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.5%CVE-2020-8566MEDIUMCeph RBD adminSecrets exposed in logs when loglevel >= 4EPSS 0.5%CVE-2023-52143HIGHWordPress WP Stripe Checkout Plugin <= 1.2.2.37 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-22464MEDIUM Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerEPSS 0.5%CVE-2021-22133The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an applicatioEPSS 0.5%CVE-2024-31245MEDIUMWordPress ConvertKit plugin <= 2.4.5 - Email Disclosure in Log File vulnerabilityEPSS 0.5%CVE-2023-44989HIGHWordPress CF7 Google Sheets Connector plugin <= 5.0.5 - Sensitive Data Exposure via Debug Log vulnerabilityEPSS 0.5%CVE-2020-12023LOWPhilips IntelliBridge Enterprise IBE Insertion of Sensitive Information into Log FileEPSS 0.5%CVE-2024-10544MEDIUMWoo Manage Fraud Orders <= 2.6.1 - Unauthenticated Information Exposure via Log FilesEPSS 0.5%CVE-2024-9621MEDIUMIo.quarkiverse.cxf:quarkus-cxf: quarkus cxf may log user password and secret to application logEPSS 0.5%CVE-2020-8565MEDIUMIncomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9EPSS 0.5%CVE-2026-49200CRITICALAcer Wave 7 router: Broken Access ControlEPSS 0.5%CVE-2025-62208MEDIUMWindows License Manager Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-62209MEDIUMWindows License Manager Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-23791MEDIUMUnnecessary data is written to log if issues during indexing occursEPSS 0.5%CVE-2022-36407CRITICALInformation Exposure Vulnerability in Hitachi Disk Array SystemsEPSS 0.5%CVE-2019-14846HIGHIn Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG EPSS 0.5%