Weaknesses of type CWE-532

857 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2026-32982HIGHOpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error LogsEPSS 0.4%CVE-2024-37270MEDIUMWordPress TrustedLogin Vendor plugin < 1.1.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-38321MEDIUMIBM Business Automation Workflow information disclosureEPSS 0.4%CVE-2025-57813MEDIUMInsertion of Sensitive Information into Log File in github.com/traPtitech/traQEPSS 0.4%CVE-2024-40636MEDIUMBasic Auth Credential Leakage to Logs After Fetch Registry Error in Steeltoe.Discovery.Eureka with Peer AwarenessEPSS 0.4%CVE-2026-87779HIGHApache Syncope: AES Secret Key disclosure via log outputEPSS 0.4%CVE-2026-54652HIGHFrigate viewer can read logs exposing admin and camera credentialsEPSS 0.4%CVE-2025-54064MEDIUMrucio-server, rucio-ui, and rucio-webui vulnerable to insertion of X-Rucio-Auth-Token in apache access logfilesEPSS 0.4%CVE-2026-43826MEDIUMApache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URLEPSS 0.4%CVE-2026-41018MEDIUMApache Airflow Providers Elasticsearch: Elasticsearch task-log handler leaks credentials embedded in the host URLEPSS 0.4%CVE-2020-15095MEDIUMSensitive information exposure through logs in npm cliEPSS 0.4%CVE-2024-47570MEDIUMAn insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all verEPSS 0.4%CVE-2025-53886MEDIUMDirectus doesn't redact tokens in Flow logsEPSS 0.4%CVE-2023-50951MEDIUMIBM QRadar Suite information disclosureEPSS 0.4%CVE-2023-32491MEDIUM Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user EPSS 0.4%CVE-2025-14432HIGHPoly Video - Sensitive Data Might Be Written to Log FileEPSS 0.4%CVE-2026-14948HIGHFrauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive Information into Log File via error log archivesEPSS 0.4%CVE-2025-24651MEDIUMWordPress WebToffee WP Backup and Migration plugin <= 1.5.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2022-27895MEDIUMA component in Foundry logging was found to be capturing sensitive information in logs.EPSS 0.4%CVE-2022-27896MEDIUMThe Foundry Code-Workbooks service was found to contain an issue leading to information disclosure.EPSS 0.4%