Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2019-25683MEDIUMFileZilla 3.40.0 Denial of Service via Local SearchEPSS 0.2%CVE-2026-47234MEDIUMAdmidio writes session IDs and auto-login cookie values to application logsEPSS 0.2%CVE-2023-6814MEDIUMInformation Exposure Vulnerability in Cosminexus Component ContainerEPSS 0.2%CVE-2026-9735MEDIUMKeyfile contents are in MongoDB Server logsEPSS 0.2%CVE-2023-22573HIGHDell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privilegEPSS 0.2%CVE-2023-41253MEDIUMBIG-IP DNS TSIG Key vulnerabilityEPSS 0.2%CVE-2023-43485MEDIUMBIGIP and BIG-IQ TACACS+ audit log VulnerabilityEPSS 0.2%CVE-2023-45241MEDIUMSensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows)EPSS 0.2%CVE-2024-2877MEDIUMVault Enterprise Leaks Sensitive HTTP Request Headers in the Audit Log When Deployed With a Performance Standby NodeEPSS 0.2%CVE-2025-1696MEDIUMExposure of Proxy Credentials in Docker Desktop LogsEPSS 0.2%CVE-2026-59302LOWPotential for logging sensitive data in Spring Cloud StreamEPSS 0.2%CVE-2026-75057MEDIUMIn JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE logEPSS 0.2%CVE-2023-40694MEDIUMIBM Watson CP4D Data Stores information disclosureEPSS 0.2%CVE-2021-3034MEDIUMCortex XSOAR: Secrets for SAML single sign-on (SSO) integration may be logged in system logsEPSS 0.2%CVE-2025-8864MEDIUMShared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logsEPSS 0.2%CVE-2025-23261MEDIUMNVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentEPSS 0.2%CVE-2025-43508MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive EPSS 0.2%CVE-2026-93982MEDIUMOpenPanel MCP Authentication Token in Query Parameter Logged PlaintextEPSS 0.2%CVE-2025-6624LOWVersions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debugEPSS 0.2%CVE-2025-2300MEDIUMInformation exposure vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVAEPSS 0.2%