Weaknesses of type CWE-532

859 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2026-66068MEDIUMRabbitMQ: Shovel DEBUG log of full state exposes decrypted URIsEPSS 0.1%CVE-2025-27496LOWSnowflake JDBC Driver client-side encryption key in DEBUG logsEPSS 0.1%CVE-2025-46329LOWSnowflake Connector for C/C++ inserts client-side encryption key in DEBUG logsEPSS 0.1%CVE-2021-21508MEDIUMDell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit thisEPSS 0.1%CVE-2023-50301LOWIBM Transformation Extender Advanced information disclosureEPSS 0.1%CVE-2026-1495MEDIUMInsertion of Sensitive Information into Log File vulnerability in AVEVA PI to CONNECT AgentEPSS 0.1%CVE-2022-45098MEDIUM Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticateEPSS 0.1%CVE-2025-68919MEDIUMFujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenancEPSS 0.1%CVE-2026-19502MEDIUMInsufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLIEPSS 0.1%CVE-2026-46467MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.1%CVE-2025-36133MEDIUMIBM App Connect Enterprise information disclosureEPSS 0.1%CVE-2024-29955MEDIUMInsertion of Sensitive Information into Brocade SANnav Log FileEPSS 0.1%CVE-2026-16689MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.1%CVE-2026-0936MEDIUMInsertion of Sensitive Information into LogfileEPSS 0.1%CVE-2026-19649MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.1%CVE-2024-11604HIGHInsertion of Sensitive Information into Log FileEPSS 0.1%CVE-2025-12996MEDIUMMedtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errorEPSS 0.1%CVE-2025-13755MEDIUMIBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase bucketsEPSS 0.1%CVE-2025-3456LOWOn affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-cEPSS 0.1%CVE-2026-0267MEDIUMGlobalProtect App: Information Exposure Vulnerability on macOSEPSS 0.1%