Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2024-55891LOWInformation Disclosure via Exception Handling/Logger in TYPO3EPSS 0.3%CVE-2026-2350MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.EPSS 0.3%CVE-2026-1292MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in Trends.EPSS 0.3%CVE-2023-38271MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%CVE-2025-1075MEDIUMLDAP credentials logged to Apache error logEPSS 0.3%CVE-2026-73457MEDIUMUnder certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.EPSS 0.3%CVE-2025-62513MEDIUMOpenBao leaks HTTPRawBody in Audit LogsEPSS 0.3%CVE-2026-32598MEDIUMOneUptime: Password Reset Token Logged at INFO LevelEPSS 0.3%CVE-2020-1624MEDIUMJunos OS Evolved: objmon logs may leak sensitive informationEPSS 0.3%CVE-2026-2605MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in TanOS.EPSS 0.3%CVE-2020-1623MEDIUMJunos OS Evolved: ev.ops file may leak sensitive informationEPSS 0.3%CVE-2025-10645MEDIUMWP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via wf-licensing.logEPSS 0.3%CVE-2021-20180—A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature wEPSS 0.3%CVE-2025-4090MEDIUMLeaked library paths in Thunderbird for AndroidEPSS 0.3%CVE-2025-5464MEDIUMInsertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker toEPSS 0.3%CVE-2025-5463MEDIUMInsertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version EPSS 0.3%CVE-2023-28443MEDIUMdirectus vulnerable to Insertion of Sensitive Information into Log FileEPSS 0.3%CVE-2024-47822MEDIUMDirectus inserts access token from query string into logsEPSS 0.3%CVE-2025-54319MEDIUMAn issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive inforEPSS 0.3%CVE-2019-18576MEDIUMDell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local fEPSS 0.3%