Weaknesses of type CWE-532

852 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2026-64800LOWIn JetBrains GoLand before 2026.2 sensitive configuration values written to log files by defaultEPSS 0.5%CVE-2023-38733MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.5%CVE-2024-39460MEDIUMJenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL inEPSS 0.5%CVE-2025-1296MEDIUMNomad Exposes Sensitive Workload Identity and Client Secret Token in Audit LogsEPSS 0.5%CVE-2024-41978HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.5%CVE-2026-20239HIGHSensitive Information Disclosure through Log Files in Splunk EnterpriseEPSS 0.5%CVE-2022-29928MEDIUMIn JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possibleEPSS 0.5%CVE-2025-31199MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS SonomEPSS 0.5%CVE-2024-31254LOWWordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2025-11248LOWSensitive Information LoggedEPSS 0.5%CVE-2023-51490MEDIUMWordPress Defender Security Plugin <= 4.1.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-82434CRITICALApache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to LogsEPSS 0.5%CVE-2023-51408MEDIUMWordPress WP Optin Wheel Plugin <= 1.4.3 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2023-51508MEDIUMWordPress Database Cleaner Plugin <= 0.9.8 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-50316MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-46231HIGHSession Token Disclosure to Internal Log Files in Splunk Add-on BuilderEPSS 0.5%CVE-2024-29959HIGHBrocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support saveEPSS 0.5%CVE-2023-20207MEDIUMA vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive iEPSS 0.5%CVE-2022-33187MEDIUMBrocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logsEPSS 0.5%CVE-2023-22481MEDIUMSensitive information exposure in the logs of greader API in FreshRSSEPSS 0.5%