Weaknesses of type CWE-117

121 results

Falta de sanitização em logs

O software escreve dados não validados diretamente nos logs sem neutralizar caracteres especiais ou sequências perigosas. Isso permite que um atacante injete conteúdo malicioso (como quebras de linha, comandos ou payloads) que será processado ou interpretado por ferramentas de análise de logs, levando a falsificação de registros, execução de código ou bypass de detecção.

Example

Um usuário envia um campo de nome contendo quebras de linha e texto malicioso. O aplicativo escreve diretamente no log: 'Usuário: Alice\nADMIN: Acesso negado revogado'. Ferramentas ou analistas lendo o log são enganadas, acreditando que o acesso foi realmente revogado.

How to mitigate

Sempre sanitize dados antes de escrever em logs: remova ou escape caracteres de controle (\n, \r, \t), use codificação apropriada (URL encoding, JSON escaping) ou substitua por espaços/asteriscos. Considere estruturado formato de logs (JSON, CEF) que lida melhor com caracteres especiais.

CVE-2024-22356MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS information disclosureEPSS 0.5%CVE-2024-0095MEDIUMCVEEPSS 0.5%CVE-2024-8297MEDIUMkitsada8621 Digital Library Management System jwt_refresh_token_middleware.go JwtRefreshAuth neutralization for logsEPSS 0.5%CVE-2026-86522MEDIUMLog injection via an unescaped password reset identity in AshAuthenticationEPSS 0.5%CVE-2019-14846HIGHIn Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG EPSS 0.5%CVE-2024-52962MEDIUMAn Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, versioEPSS 0.5%CVE-2024-12580MEDIUMLogs Debug Injection in danny-avila/librechatEPSS 0.5%CVE-2024-9026LOWPHP-FPM logs from children may be alteredEPSS 0.5%CVE-2024-8334MEDIUMmaster-nan Sweet-CMS log.go LogHandler neutralization for logsEPSS 0.5%CVE-2023-46713MEDIUMAn improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may alEPSS 0.5%CVE-2023-36924MEDIUMLog Injection vulnerability in SAP ERP Defense Forces and Public SecurityEPSS 0.5%CVE-2023-31405MEDIUMLog Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)EPSS 0.4%CVE-2024-31845MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs.EPSS 0.4%CVE-2023-37275LOWSystem logs spoofable in Auto-GPT via ANSI control sequencesEPSS 0.4%CVE-2026-10745HIGHImproper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log InjectioEPSS 0.4%CVE-2024-32474HIGHSentry's superuser cleartext password leaked in logsEPSS 0.4%CVE-2019-14858HIGHA vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub paramEPSS 0.4%CVE-2023-0595MEDIUMA CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious pEPSS 0.4%CVE-2020-14332MEDIUMA flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensEPSS 0.4%CVE-2023-6002MEDIUMLog InjectionEPSS 0.4%