Weaknesses of type CWE-532

850 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2020-10712HIGHA flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry oEPSS 1.0%CVE-2016-10362Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth creEPSS 1.0%CVE-2022-24875MEDIUMPotential Secrets being logged to disk in CVEProject/cve-servicesEPSS 1.0%CVE-2022-20807MEDIUMCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 1.0%CVE-2018-1072MEDIUMovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of tEPSS 1.0%CVE-2021-34800Sensitive information could be loggedEPSS 1.0%CVE-2024-29945HIGHSplunk Authentication Token Exposure in Debug Log in Splunk EnterpriseEPSS 0.9%CVE-2022-20806MEDIUMCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 0.9%CVE-2020-5389CRITICALDell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information discEPSS 0.9%CVE-2018-3817When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive informatioEPSS 0.9%CVE-2022-20768MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure VulnerabilityEPSS 0.9%CVE-2022-20809MEDIUMCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 0.9%CVE-2025-21319MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-21321MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-21320MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-21318MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-21316MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-54236MEDIUMvLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic routerEPSS 0.9%CVE-2021-36544HIGHIncorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.EPSS 0.9%CVE-2021-27022A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being loggEPSS 0.9%