Weaknesses of type CWE-532

852 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2024-2302MEDIUMEasy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information ExposureEPSS 0.6%CVE-2024-23686MEDIUMDependencyCheck Debug Mode Logging of NVD API KeyEPSS 0.6%CVE-2025-31213HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, mEPSS 0.6%CVE-2023-33001HIGHJenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the buildEPSS 0.6%CVE-2025-24457MEDIUMIn JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logsEPSS 0.6%CVE-2023-0436MEDIUMSecret logging may occur in debug mode of Atlas Operator EPSS 0.6%CVE-2020-11932LOWSubiquity server installer logged LUKS full disk encryption passwordEPSS 0.6%CVE-2018-3828Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exceptiEPSS 0.6%CVE-2025-59258MEDIUMWindows Active Directory Federation Services (ADFS) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-49923MEDIUMEnterprise Search Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2026-21222MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-6687MEDIUMElastic Agent Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2021-39011MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2024-31259HIGHWordPress SearchIQ plugin <= 4.5 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.6%CVE-2024-34550MEDIUMWordPress Dynamics 365 Integration plugin <= 1.3.17 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2022-2721HIGHIn affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plainEPSS 0.6%CVE-2024-35196LOWSlack integration leaks sensitive information in logs in SentryEPSS 0.6%CVE-2020-14330MEDIUMAn Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content aEPSS 0.6%CVE-2025-31479HIGHcanonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception outputEPSS 0.6%CVE-2022-23716MEDIUMA flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in dEPSS 0.6%