Weaknesses of type CWE-532

852 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2023-22362HIGHSUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information frEPSS 0.8%CVE-2022-43936MEDIUMBrocade Fabric OS switch passwords when debugging is enabledEPSS 0.8%CVE-2021-37709MEDIUMInsecure direct object reference of log files of the Import/Export featureEPSS 0.8%CVE-2021-23046On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from AcceEPSS 0.8%CVE-2025-24169HIGHA logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be aEPSS 0.8%CVE-2024-0831MEDIUMVault May Expose Sensitive Information When Configuring An Audit Log DeviceEPSS 0.8%CVE-2022-28859MEDIUMOn F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-iEPSS 0.8%CVE-2024-27784HIGHMultiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may alloEPSS 0.8%CVE-2022-0338MEDIUMInsertion of Sensitive Information into Log File in delgan/loguruEPSS 0.8%CVE-2019-14885MEDIUMA flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security aEPSS 0.7%CVE-2026-31987HIGHApache Airflow: JWT token appearing in logsEPSS 0.7%CVE-2020-3447MEDIUMCisco Email Security Appliance and Cisco Content Security Management Appliance Information Disclosure VulnerabilityEPSS 0.7%CVE-2024-52067MEDIUMApache NiFi: Potential Insertion of Sensitive Parameter Values in Debug LogEPSS 0.7%CVE-2020-2044LOWPAN-OS: Passwords may be logged in clear text while storing operational command (op command) historyEPSS 0.7%CVE-2020-2043LOWPAN-OS: Passwords may be logged in clear text when using after-change-detail custom syslog field for config logsEPSS 0.7%CVE-2026-20818MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-3902MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5EPSS 0.7%CVE-2023-3993MEDIUMInsertion of Sensitive Information into Log File in GitLabEPSS 0.7%CVE-2025-26795HIGHApache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driverEPSS 0.7%CVE-2025-26864HIGHApache IoTDB: Exposure of Sensitive Information in IoTDB OpenID AuthenticationEPSS 0.7%