Fallos del tipo CWE-117

121 resultados

Injeção em logs (Log Injection)

O software escreve dados do usuário ou de fontes externas diretamente nos logs sem sanitização, permitindo que um atacante injete mensagens falsas, quebre a estrutura do log ou esconda evidências. Isso compromete a auditoria, facilita ataques de negação de serviço e pode levar a falsificação de registros de segurança.

Ejemplo

Um aplicativo web registra logins assim: `log.info("Usuário: " + username + " realizou login")`. Um atacante cria uma conta chamada `admin%0aUSUÁRIO AUTORIZADO: admin` e faz login, injetando uma linha fake no log que simula uma ação de administrador que nunca ocorreu.

Cómo mitigar

Sanitize sempre entradas de usuário antes de registrar (remova quebras de linha, caracteres de controle), use estrutura de logging estruturada (JSON, key-value) em vez de concatenação, e valide/filtre dados na origem. Implemente logs imutáveis ou com assinatura criptográfica para auditoria sensível.

CVE-2024-22356MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS information disclosureEPSS 0.5%CVE-2024-0095MEDIUMCVEEPSS 0.5%CVE-2024-8297MEDIUMkitsada8621 Digital Library Management System jwt_refresh_token_middleware.go JwtRefreshAuth neutralization for logsEPSS 0.5%CVE-2026-86522MEDIUMLog injection via an unescaped password reset identity in AshAuthenticationEPSS 0.5%CVE-2019-14846HIGHIn Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG EPSS 0.5%CVE-2024-52962MEDIUMAn Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, versioEPSS 0.5%CVE-2024-12580MEDIUMLogs Debug Injection in danny-avila/librechatEPSS 0.5%CVE-2024-9026LOWPHP-FPM logs from children may be alteredEPSS 0.5%CVE-2024-8334MEDIUMmaster-nan Sweet-CMS log.go LogHandler neutralization for logsEPSS 0.5%CVE-2023-46713MEDIUMAn improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may alEPSS 0.5%CVE-2023-36924MEDIUMLog Injection vulnerability in SAP ERP Defense Forces and Public SecurityEPSS 0.5%CVE-2023-31405MEDIUMLog Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)EPSS 0.4%CVE-2024-31845MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs.EPSS 0.4%CVE-2023-37275LOWSystem logs spoofable in Auto-GPT via ANSI control sequencesEPSS 0.4%CVE-2026-10745HIGHImproper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log InjectioEPSS 0.4%CVE-2024-32474HIGHSentry's superuser cleartext password leaked in logsEPSS 0.4%CVE-2019-14858HIGHA vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub paramEPSS 0.4%CVE-2023-0595MEDIUMA CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious pEPSS 0.4%CVE-2020-14332MEDIUMA flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensEPSS 0.4%CVE-2023-6002MEDIUMLog InjectionEPSS 0.4%