Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2026-8482MEDIUMInformation leak in NSRPC client historyEPSS 0.2%CVE-2023-25682MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.2%CVE-2026-25211LOWLlama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.EPSS 0.2%CVE-2025-11446HIGHInsertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain CredentialsEPSS 0.2%CVE-2024-6977MEDIUMCato Networks Windows SDP Client Sensitive data in trace logs can lead to account takeoverEPSS 0.2%CVE-2022-0010HIGHQCS 800xA Vulnerability identified in system log filesEPSS 0.2%CVE-2025-38745MEDIUMDell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in EPSS 0.2%CVE-2025-43303MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 2EPSS 0.2%CVE-2026-14163HIGHIn affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment vaEPSS 0.2%CVE-2022-0021LOWGlobalProtect App: Information Exposure Vulnerability When Using Connect Before LogonEPSS 0.2%CVE-2023-31207MEDIUMAutomation user secret logged to Apache access logEPSS 0.2%CVE-2025-20373LOWSensitive Information Disclosure in “_internal“ index through Splunk Add-On for Palo Alto NetworksEPSS 0.2%CVE-2025-66910MEDIUMTurms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. ThEPSS 0.2%CVE-2023-32283MEDIUMInsertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.0 may allow an autheEPSS 0.2%CVE-2022-43935MEDIUMSwitch passwords and authorization IDs are printed in the embedded MLS DB fileEPSS 0.2%CVE-2021-3429MEDIUMsensitive data exposure in cloud-init logsEPSS 0.2%CVE-2023-45825MEDIUMToken in custom credentials object can leak through logs in ydb-go-sdkEPSS 0.2%CVE-2025-2327MEDIUMFlashArray KEK Logging VulnerabilityEPSS 0.2%CVE-2024-12292MEDIUMInsertion of Sensitive Information into Log File in GitLabEPSS 0.2%CVE-2023-1550MEDIUMNGINX Agent vulnerability CVE-2023-1550EPSS 0.2%