Weaknesses of type CWE-532

852 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2025-20231HIGHSensitive Information Disclosure in Splunk Secure Gateway AppEPSS 0.5%CVE-2023-41308Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.EPSS 0.5%CVE-2020-8563MEDIUMSecret leaks in logs for vSphere Provider kube-controller-managerEPSS 0.5%CVE-2020-1753MEDIUMA security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all EPSS 0.5%CVE-2023-6746HIGHSensitive Information in Log File in GitHub Enterprise Server EPSS 0.5%CVE-2024-31249MEDIUMWordPress Subscribe To Comments Reloaded plugin <= 220725 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-31298MEDIUMWordPress User Spam Remover plugin <= 1.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-31247MEDIUMWordPress FG Drupal to WordPress plugin <= 3.70.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-13818MEDIUMRegistration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction <= 3.8.4 - Sensitive Information Exposure via Log FilesEPSS 0.5%CVE-2025-22275CRITICALiTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by readinEPSS 0.5%CVE-2026-41184MEDIUMServiceAccount token disclosure via install-cni container logsEPSS 0.5%CVE-2024-34527HIGHspaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged.EPSS 0.5%CVE-2023-26207LOWAn insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.1EPSS 0.5%CVE-2023-38067MEDIUMIn JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2023-38064MEDIUMIn JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2023-47131HIGHThe N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.EPSS 0.5%CVE-2024-3165MEDIUMDatabase Credential Exposure in the LogsEPSS 0.5%CVE-2024-22352MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.5%CVE-2024-37286MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.5%CVE-2025-31788MEDIUMWordPress AIO Performance Profiler, Monitor, Optimize, Compress & Debug plugin <= 1.3 - Sensitive Data Exposure vulnerabilityEPSS 0.5%