Fallos del tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2024-8609HIGHImproper Access Control in Oceanic Software's ValeAppEPSS 0.5%CVE-2024-30514MEDIUMWordPress Paid Memberships Pro – Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-30511MEDIUMWordPress FG PrestaShop to WooCommerce plugin <= 4.45.1 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-31353MEDIUMWordPress Slideshow Gallery LITE plugin <= 1.7.8 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-27900MEDIUMTerraform Provider Debug Logs Vulnerable to Sensitive Information ExposureEPSS 0.5%CVE-2022-4858MEDIUMInsertion of Sensitive Information into Log FileEPSS 0.5%CVE-2024-23758HIGHAn issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.loEPSS 0.5%CVE-2020-8564MEDIUMDocker config secrets leaked when file is malformed and loglevel >= 4EPSS 0.5%CVE-2023-32468MEDIUM Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability. A remote malicious EPSS 0.5%CVE-2025-59355MEDIUMApache Linkis: Password ExposureEPSS 0.5%CVE-2026-9699MEDIUMMattermost Agents plugin logs unsanitized OpenAI API keys on authentication errorsEPSS 0.5%CVE-2026-68873MEDIUMWindows Program Compatibility Assistant Service Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-8365MEDIUMVault Leaks AppRole Client Tokens And Accessor in Audit LogEPSS 0.5%CVE-2022-43937MEDIUMBrocade SANnav Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-47913MEDIUMAn issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2.EPSS 0.5%CVE-2026-46514MEDIUMFrogman: Plaintext passwords and secrets persisted to audit logEPSS 0.5%CVE-2025-59197MEDIUMWindows ETL Channel Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-59203MEDIUMWindows State Repository API Server File Information Disclosure VulnerabilityEPSS 0.4%CVE-2017-2592MEDIUMpython-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError classEPSS 0.4%CVE-2025-40603MEDIUMA potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrEPSS 0.4%