Fallos del tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2023-5499HIGHShenzhen Reachfar v28 information exposureEPSS 0.6%CVE-2022-44624MEDIUMIn JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special charactersEPSS 0.6%CVE-2024-42349MEDIUMFOG has a Log Information DisclosureEPSS 0.6%CVE-2021-36278HIGHDell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local EPSS 0.6%CVE-2024-37283MEDIUMElastic Agent Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2022-3293LOWEmail addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 priEPSS 0.6%CVE-2024-0472LOWcode-projects Dormitory Management System modifyuser.php information disclosureEPSS 0.6%CVE-2024-33637HIGHWordPress Solid Affiliate plugin <= 1.9.1 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.6%CVE-2023-23591MEDIUMThe Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs EPSS 0.6%CVE-2024-28186HIGHSMTP Mail Credentials Disclosed in Error Log in freescoutEPSS 0.6%CVE-2023-46667HIGHFleet Server Insertion of Sensitive Information into Log FileEPSS 0.5%CVE-2022-49037MEDIUMInsertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allowEPSS 0.5%CVE-2024-32788MEDIUMWordPress FG Joomla to Wordpress plugin <= 4.20.2 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2020-5262HIGHGitHub personal access token leaking into temporary EasyBuild (debug) logsEPSS 0.5%CVE-2023-20885MEDIUMCF workflows leak credentials in system audit logsEPSS 0.5%CVE-2022-23506MEDIUMSpinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer buildsEPSS 0.5%CVE-2018-16859MEDIUMExecution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' paEPSS 0.5%CVE-2023-32478CRITICAL Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged maliEPSS 0.5%CVE-2021-3039LOWPrisma Cloud Compute: User role authorization secret for Console leaked through log file exportEPSS 0.5%CVE-2025-24556HIGHWordPress MooWoodle plugin <= 3.2.4 - Sensitive Data Exposure vulnerabilityEPSS 0.5%