Weaknesses of type CWE-532

859 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2026-2401LOWCWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when EPSS 0.1%CVE-2025-48635HIGHIn multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. ThiEPSS 0.1%CVE-2026-21808MEDIUMHCL BigFix Quantum Risk Analyzer is affected by logging sensitive informationEPSS 0.1%CVE-2026-21786LOWHCL Sametime for iOS is affected by sensitive information disclosureEPSS 0.1%CVE-2022-33688LOWSensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers witEPSS 0.1%CVE-2022-33697LOWSensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with EPSS 0.1%CVE-2026-75573MEDIUMMongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are SuppliedEPSS 0.1%CVE-2025-32016MEDIUMMicrosoft Identity Web Exposes Client Secrets and Certificate Information in Service LogsEPSS 0.1%CVE-2026-17442MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.1%CVE-2026-0520LOWA potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticEPSS 0.1%CVE-2026-81530MEDIUMKMS master key exposure via unredacted credential serialization in driver settings stringEPSS 0.1%CVE-2025-63729CRITICALAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA CertifEPSS 0.1%CVE-2026-14442MEDIUMInformation exposure vulnerability in the job scheduling component of SANnav before 3.0.1aEPSS —CVE-2026-82716MEDIUMBotslab G980H Dashcams Insertion of Sensitive Information into Log FileEPSS —CVE-2026-63208MEDIUMZammad: Microsoft Graph error logs expose partially masked OAuth access tokensEPSS —CVE-2026-14443HIGHIncomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1aEPSS —CVE-2026-85417MEDIUMIncomplete property masking in the SANnav logging subsystemEPSS —CVE-2026-82372HIGHImproper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav before 3.0.1.aEPSS —CVE-2026-82371HIGHPlaintext exposure of sensitive authentication data in SANnav discovery service log filesEPSS —