Weaknesses of type CWE-532

857 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2024-32757MEDIUMAmerican Dynamics Illustra Essentials Gen 4 - Linux Credential LeakEPSS 0.4%CVE-2026-65589MEDIUMn8n before 1.123.64 Credential Exposure via LLM Node Execution DataEPSS 0.4%CVE-2025-27555MEDIUMApache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cliEPSS 0.4%CVE-2024-37930MEDIUMWordPress SmartMag theme < 10.1.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-43990MEDIUMWordPress Masterstudy LMS Starter theme <= 1.1.8 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2022-26322MEDIUMPossible Insertion of Sensitive Information into Log File Vulnerability in Identity ManagerEPSS 0.4%CVE-2026-34164MEDIUMValtimo: Sensitive data exposure through inbox message logging in InboxHandlingServiceEPSS 0.4%CVE-2024-5908MEDIUMGlobalProtect App: Encrypted Credential Exposure via Log FilesEPSS 0.4%CVE-2024-32811MEDIUMWordPress USPS Shipping for WooCommerce – Live Rates plugin <= 1.9.4 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2025-20329MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-46171MEDIUMIBM DS8900F information disclosureEPSS 0.4%CVE-2025-31514LOWA insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS EPSS 0.4%CVE-2026-65945MEDIUMApache Ranger: Logs contain replayable JWT bearer tokensEPSS 0.4%CVE-2024-6104MEDIUMgo-retryablehttp can leak basic auth credentials to log filesEPSS 0.4%CVE-2022-40979MEDIUMIn JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executableEPSS 0.4%CVE-2026-68969MEDIUMApache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartextEPSS 0.4%CVE-2025-25013MEDIUMElastic Defend Insertion of Sensitive Information into Log FilesEPSS 0.4%CVE-2019-5634MEDIUMHickory Smart Lock Insecure Logging on AndroidEPSS 0.4%CVE-2024-13416MEDIUMUsing API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has relEPSS 0.4%CVE-2023-28441HIGHsmartCARS 3 Password Stored as plain text in Error LogEPSS 0.4%