Weaknesses of type CWE-532

852 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2024-8609HIGHImproper Access Control in Oceanic Software's ValeAppEPSS 0.5%CVE-2024-30514MEDIUMWordPress Paid Memberships Pro – Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-30511MEDIUMWordPress FG PrestaShop to WooCommerce plugin <= 4.45.1 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-31353MEDIUMWordPress Slideshow Gallery LITE plugin <= 1.7.8 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-27900MEDIUMTerraform Provider Debug Logs Vulnerable to Sensitive Information ExposureEPSS 0.5%CVE-2024-23758HIGHAn issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.loEPSS 0.5%CVE-2022-4858MEDIUMInsertion of Sensitive Information into Log FileEPSS 0.5%CVE-2020-8564MEDIUMDocker config secrets leaked when file is malformed and loglevel >= 4EPSS 0.5%CVE-2023-32468MEDIUM Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability. A remote malicious EPSS 0.5%CVE-2025-59355MEDIUMApache Linkis: Password ExposureEPSS 0.5%CVE-2026-9699MEDIUMMattermost Agents plugin logs unsanitized OpenAI API keys on authentication errorsEPSS 0.5%CVE-2026-68873MEDIUMWindows Program Compatibility Assistant Service Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-8365MEDIUMVault Leaks AppRole Client Tokens And Accessor in Audit LogEPSS 0.5%CVE-2022-43937MEDIUMBrocade SANnav Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-47913MEDIUMAn issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2.EPSS 0.5%CVE-2026-46514MEDIUMFrogman: Plaintext passwords and secrets persisted to audit logEPSS 0.5%CVE-2026-22038HIGHAutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration BlocksEPSS 0.5%CVE-2025-59203MEDIUMWindows State Repository API Server File Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-59197MEDIUMWindows ETL Channel Information Disclosure VulnerabilityEPSS 0.4%CVE-2017-2592MEDIUMpython-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError classEPSS 0.4%