Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2025-64650MEDIUMIBM Storage Defender - Resiliency Service Information DisclosureEPSS 0.3%CVE-2020-6653LOWSensitive date stored in logcat fileEPSS 0.3%CVE-2023-1786MEDIUMsensitive data exposure in cloud-init logsEPSS 0.3%CVE-2026-81715HIGHopenssl_encrypt before 1.4.9 Credential Exposure via Debug OutputEPSS 0.3%CVE-2020-26199MEDIUMDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentiaEPSS 0.3%CVE-2026-74870HIGHopenssl_encrypt before 1.4.8 Hardware Pepper Information DisclosureEPSS 0.3%CVE-2026-24762MEDIUMRustFS Logs Sensitive Credentials in PlaintextEPSS 0.3%CVE-2022-35202MEDIUMA security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the EPSS 0.3%CVE-2022-31186LOWLeakage of excessive information into log in next-authEPSS 0.3%CVE-2025-43426MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may beEPSS 0.3%CVE-2019-18244—In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts arEPSS 0.3%CVE-2023-28630MEDIUMSensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocdEPSS 0.3%CVE-2024-27154MEDIUMPasswords are stored in clear-text logs.EPSS 0.3%CVE-2025-41690HIGHEndress+Hauser: Proline 10 Maintenance credentials may be exposed under certain conditionsEPSS 0.3%CVE-2021-36340HIGHDell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulneEPSS 0.3%CVE-2021-21598LOWDell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with pEPSS 0.3%CVE-2021-21558HIGHDell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator EPSS 0.3%CVE-2021-21597HIGHDell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical acceEPSS 0.3%CVE-2021-3684—A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plainteEPSS 0.2%CVE-2025-13611LOWInsertion of Sensitive Information into Log File in GitLabEPSS 0.2%