Weaknesses of type CWE-532

857 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2026-35185HIGHHAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addressesEPSS 0.4%CVE-2026-92918HIGHadmin3 through 3.0.0 Session Token Disclosure via Audit LogEPSS 0.4%CVE-2018-1075MEDIUMovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run andEPSS 0.4%CVE-2024-9453MEDIUMJenkins-image: sensitive data disclosure when using openshift jenkins imageEPSS 0.4%CVE-2024-49816MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.4%CVE-2024-0935MEDIUMInsertion of Sensitive Information into Log File vulnerabilities affecting DELMIA Apriso Release 2019 through Release 2024EPSS 0.4%CVE-2024-12226MEDIUMIn affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in cleEPSS 0.4%CVE-2021-20191—A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log featureEPSS 0.3%CVE-2023-46668MEDIUMElastic Endpoint Insertion of Sensitive Information into Log FileEPSS 0.3%CVE-2026-78174CRITICALWatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsEPSS 0.3%CVE-2019-10194MEDIUMSensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. PasswordEPSS 0.3%CVE-2023-4688MEDIUMSensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433.EPSS 0.3%CVE-2024-34798MEDIUMWordPress Debug Log – Manger Tool plugin <= 1.4.5 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-23374HIGHDell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information EPSS 0.3%CVE-2020-2048LOWPAN-OS: System proxy passwords may be logged in clear text while viewing system stateEPSS 0.3%CVE-2023-46175MEDIUMIBM Cloud Pak for Multicloud Management information disclosureEPSS 0.3%CVE-2025-62879MEDIUMRancher Backup Operator pod's logs leak S3 tokensEPSS 0.3%CVE-2022-4311MEDIUM An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with EPSS 0.3%CVE-2021-20178—A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature wEPSS 0.3%CVE-2025-15332MEDIUMTanium addressed an information disclosure vulnerability in Threat Response.EPSS 0.3%