Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2024-25959HIGHDell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low priEPSS 0.2%CVE-2026-11819MEDIUMCommunity.general: community.general keyring_info — os keyring passphrase returned in plaintextEPSS 0.2%CVE-2025-0976MEDIUMInformation Exposure Vulnerability in Hitachi Configuration Manager, Hitachi Ops Center API Configuration ManagerEPSS 0.2%CVE-2026-95815HIGHOpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL LoggingEPSS 0.2%CVE-2025-49846MEDIUMwire-ios accidentally logs message contentsEPSS 0.2%CVE-2025-3911MEDIUMExposure in Docker Desktop logs of environment variables configured for running containersEPSS 0.2%CVE-2025-46752MEDIUMA insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to infEPSS 0.2%CVE-2026-84513MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 EPSS 0.2%CVE-2026-19483HIGHThe following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higherEPSS 0.2%CVE-2025-46614LOWIn Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of SensEPSS 0.2%CVE-2026-84527MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS SequoiaEPSS 0.2%CVE-2025-1053HIGHBrocade SANnav encryption key is logged in the debug logsEPSS 0.2%CVE-2026-40633HIGHDell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information iEPSS 0.2%CVE-2026-49810HIGHDell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability.EPSS 0.2%CVE-2026-4788HIGHMultiple Vulnerabilities affect IBM Tivoli Netcool ImpactEPSS 0.2%CVE-2026-71474HIGHInsights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx responseEPSS 0.2%CVE-2024-25957MEDIUMDell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. EPSS 0.2%CVE-2026-9751MEDIUMSensitive data could be written to mongod.logEPSS 0.2%CVE-2024-42344MEDIUMA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive inEPSS 0.2%CVE-2024-43781MEDIUMA vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in conneEPSS 0.2%