Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2026-41185MEDIUMServiceAccount token disclosure via Azure IPAM CNI plugin logsEPSS 0.3%CVE-2024-42407HIGHInsertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authentiEPSS 0.3%CVE-2026-66780MEDIUMSubmariner-operator: broker serviceaccount secret (token + ca) logged in full at trace verbosityEPSS 0.3%CVE-2024-38862MEDIUMSNMP and IMPI secrets written to audit logEPSS 0.3%CVE-2024-23840MEDIUM`goreleaser release --debug` shows secretsEPSS 0.3%CVE-2024-55891LOWInformation Disclosure via Exception Handling/Logger in TYPO3EPSS 0.3%CVE-2026-1292MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in Trends.EPSS 0.3%CVE-2026-2350MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.EPSS 0.3%CVE-2025-1075MEDIUMLDAP credentials logged to Apache error logEPSS 0.3%CVE-2023-38271MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%CVE-2026-73457MEDIUMUnder certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.EPSS 0.3%CVE-2026-81705HIGHopenssl-encrypt before 1.4.9 Password Cleartext Leak via DebugEPSS 0.3%CVE-2025-62513MEDIUMOpenBao leaks HTTPRawBody in Audit LogsEPSS 0.3%CVE-2020-1624MEDIUMJunos OS Evolved: objmon logs may leak sensitive informationEPSS 0.3%CVE-2020-1623MEDIUMJunos OS Evolved: ev.ops file may leak sensitive informationEPSS 0.3%CVE-2019-25766HIGHRenovate before 19.38.7 Credential Exposure via Go ModulesEPSS 0.3%CVE-2025-10645MEDIUMWP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via wf-licensing.logEPSS 0.3%CVE-2020-37267HIGHRenovate 19.180.0 before 23.25.1 Token Leakage via LogsEPSS 0.3%CVE-2021-20180—A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature wEPSS 0.3%CVE-2025-4090MEDIUMLeaked library paths in Thunderbird for AndroidEPSS 0.3%