Fallos del tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2025-20231HIGHSensitive Information Disclosure in Splunk Secure Gateway AppEPSS 0.5%CVE-2023-41308Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.EPSS 0.5%CVE-2020-8563MEDIUMSecret leaks in logs for vSphere Provider kube-controller-managerEPSS 0.5%CVE-2023-6746HIGHSensitive Information in Log File in GitHub Enterprise Server EPSS 0.5%CVE-2020-1753MEDIUMA security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all EPSS 0.5%CVE-2024-31298MEDIUMWordPress User Spam Remover plugin <= 1.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-31247MEDIUMWordPress FG Drupal to WordPress plugin <= 3.70.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-31249MEDIUMWordPress Subscribe To Comments Reloaded plugin <= 220725 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-13818MEDIUMRegistration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction <= 3.8.4 - Sensitive Information Exposure via Log FilesEPSS 0.5%CVE-2025-22275CRITICALiTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by readinEPSS 0.5%CVE-2026-41184MEDIUMServiceAccount token disclosure via install-cni container logsEPSS 0.5%CVE-2024-34527HIGHspaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged.EPSS 0.5%CVE-2023-26207LOWAn insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.1EPSS 0.5%CVE-2023-38067MEDIUMIn JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2023-38064MEDIUMIn JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2023-47131HIGHThe N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.EPSS 0.5%CVE-2024-3165MEDIUMDatabase Credential Exposure in the LogsEPSS 0.5%CVE-2024-22352MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.5%CVE-2024-37286MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.5%CVE-2025-31788MEDIUMWordPress AIO Performance Profiler, Monitor, Optimize, Compress & Debug plugin <= 1.3 - Sensitive Data Exposure vulnerabilityEPSS 0.5%