Weaknesses of type CWE-532

850 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2026-34487HIGHApache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer tokenEPSS 0.4%CVE-2024-30523MEDIUMWordPress Paid Memberships Pro – Mailchimp Add On plugin <= 2.3.4 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-33922MEDIUMWordPress WP Media Cleaner plugin <= 6.7.2 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2023-49921MEDIUMAn issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw cEPSS 0.4%CVE-2025-62232HIGHApache APISIX: basic-auth logs plaintext credentials at info levelEPSS 0.4%CVE-2024-22339MEDIUMIBM UrbanCode Deploy information disclosureEPSS 0.4%CVE-2024-25923MEDIUMWordPress Community by PeepSo plugin <= 6.2.7.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-32686MEDIUMWordPress Backup Migration plugin <= 1.4.3 - Sensitive Data Exposure via Log vulnerabilityEPSS 0.4%CVE-2024-22138MEDIUMWordPress Seraphinite Accelerator plugin <= 2.20.47 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-37205MEDIUMWordPress affiliate-toolkit plugin <= 3.4.4 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-32513MEDIUMWordPress Product Feed PRO for WooCommerce plugin <= 13.3.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-23760LOWCleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json andEPSS 0.4%CVE-2024-36127HIGHapko Exposure of HTTP basic auth credentials in log outputEPSS 0.4%CVE-2022-44587MEDIUMWordPress WP 2FA plugin <= 2.6.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2026-22038HIGHAutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration BlocksEPSS 0.4%CVE-2026-28943HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.4%CVE-2026-28987HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.4%CVE-2025-11008CRITICALCE21 Suite <= 2.3.1 - Unauthenticated Sensitive Information Exposure to Privilege EscalationEPSS 0.4%CVE-2025-66236HIGHApache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UIEPSS 0.4%CVE-2021-22533MEDIUMPossible Insertion of Sensitive Information into Log File VulnerabilityEPSS 0.4%