Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2021-21601HIGHDell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CISEPSS 0.2%CVE-2025-6711MEDIUMIncomplete Redaction of Sensitive Information in MongoDB Server LogsEPSS 0.2%CVE-2021-32801MEDIUMExceptions may have logged Encryption-at-Rest key content in Nextcloud serverEPSS 0.2%CVE-2023-22447LOWInsertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a prEPSS 0.2%CVE-2025-24145LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS SEPSS 0.2%CVE-2022-2084MEDIUMsensitive data exposure in cloud-init logsEPSS 0.2%CVE-2025-6391HIGHJSON Web Token (JWT) Exposure in Log FilesEPSS 0.2%CVE-2025-46777LOWA insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 EPSS 0.2%CVE-2024-24272HIGHAn issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked EPSS 0.2%CVE-2022-31239MEDIUMDell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerabilityEPSS 0.2%CVE-2022-27888MEDIUMThe Foundry Issues service was found to be logging in a manner that captured session tokens.EPSS 0.2%CVE-2022-27636MEDIUMOn F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prEPSS 0.2%CVE-2020-10052—A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data,EPSS 0.2%CVE-2025-66411HIGHCoder logged sensitive objects unsanitizedEPSS 0.2%CVE-2026-59301LOWPotential for logging sensitive data in Spring Cloud Function AzureEPSS 0.2%CVE-2024-5557MEDIUMCWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attackeEPSS 0.2%CVE-2021-36318MEDIUMDell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentiaEPSS 0.2%CVE-2025-43423LOWA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, mEPSS 0.2%CVE-2025-43354MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 2EPSS 0.2%CVE-2023-23505LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.6.3, macOS VentEPSS 0.2%