Weaknesses of type CWE-532

852 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2019-1961MEDIUMCisco Enterprise NFV Infrastructure Software Web Portal Arbitrary File Read VulnerabilityEPSS 1.9%CVE-2019-14864MEDIUMAnsible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it EPSS 1.9%CVE-2022-36321MEDIUMIn JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some casesEPSS 1.8%CVE-2019-10195MEDIUMA flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way thEPSS 1.8%CVE-2019-11250MEDIUMKubernetes client-go logs authorization headers at debug verbosity levelsEPSS 1.8%CVE-2018-1241Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP paEPSS 1.6%CVE-2024-47083HIGHPower Platform Terraform Provider has Improper Masking of Secrets in LogsEPSS 1.6%CVE-2019-1953MEDIUMCisco Enterprise NFV Infrastructure Software Password Recovery VulnerabilityEPSS 1.5%CVE-2019-11283HIGHPassword leak in smbdriver logsEPSS 1.5%CVE-2018-1117MEDIUMovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManaEPSS 1.4%CVE-2020-14518MEDIUMPhilips DreamMapper Insertion of Sensitive Information into Log FileEPSS 1.3%CVE-2023-34223MEDIUMIn JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some casesEPSS 1.3%CVE-2019-11293HIGHUAA logs all query parameters with debug logging levelEPSS 1.3%CVE-2020-7021Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is EPSS 1.3%CVE-2020-11643MEDIUMGateManager Information Disclosure VulnerabilityEPSS 1.3%CVE-2019-13515OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.EPSS 1.3%CVE-2019-11290HIGHCloud Foundry UAA logs query parameters in tomcat access fileEPSS 1.3%CVE-2022-24757HIGHSensitive Auth & Cookie data stored in Jupyter server logsEPSS 1.3%CVE-2025-24362HIGHCodeQL GitHub Action failed workflow writes GitHub PAT to debug artifactsEPSS 1.2%CVE-2024-52940HIGHAnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network trafficEPSS 1.2%