Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2024-7586MEDIUMInsertion of Sensitive Information into Log File in GitLabEPSS 0.3%CVE-2019-19756HIGHAn internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updatesEPSS 0.3%CVE-2025-34188HIGHVasion Print (formerly PrinterLogic) Local Log Disclosure of Cleartext SessionsEPSS 0.3%CVE-2025-52893MEDIUMOpenBao May Leak Sensitive Information in Logs When Processing Malformed DataEPSS 0.3%CVE-2023-42937MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watEPSS 0.3%CVE-2023-28351LOWAn issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student applicatiEPSS 0.3%CVE-2026-45679MEDIUMOpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messagesEPSS 0.3%CVE-2024-29957HIGHEncryption key is stored in the DR log filesEPSS 0.3%CVE-2024-40585MEDIUMAn insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, versioEPSS 0.3%CVE-2026-56457MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive informationEPSS 0.3%CVE-2026-6720HIGHCalicoctl leaks cluster credentials to stderr when verbose logging is enabledEPSS 0.3%CVE-2024-7577MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.3%CVE-2023-40425MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14, macOS Monterey 1EPSS 0.3%CVE-2025-2092HIGHRemote site authentication secrets written to web logEPSS 0.3%CVE-2024-41824MEDIUMIn JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific casesEPSS 0.3%CVE-2024-29177LOWDell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive informatiEPSS 0.3%CVE-2024-55578MEDIUMZammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.EPSS 0.3%CVE-2026-76375MEDIUMInformation Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAREPSS 0.3%CVE-2026-76374MEDIUMInformation Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOAREPSS 0.3%CVE-2026-21766MEDIUMHCL Digital Experience and Digital Experience Compose insufficiently protects credentialsEPSS 0.3%