Fallos del tipo CWE-532

852 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2025-40603MEDIUMA potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrEPSS 0.4%CVE-2024-30523MEDIUMWordPress Paid Memberships Pro – Mailchimp Add On plugin <= 2.3.4 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-34487HIGHApache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer tokenEPSS 0.4%CVE-2024-33922MEDIUMWordPress WP Media Cleaner plugin <= 6.7.2 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2023-49921MEDIUMAn issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw cEPSS 0.4%CVE-2025-62232HIGHApache APISIX: basic-auth logs plaintext credentials at info levelEPSS 0.4%CVE-2024-22339MEDIUMIBM UrbanCode Deploy information disclosureEPSS 0.4%CVE-2024-32686MEDIUMWordPress Backup Migration plugin <= 1.4.3 - Sensitive Data Exposure via Log vulnerabilityEPSS 0.4%CVE-2024-22138MEDIUMWordPress Seraphinite Accelerator plugin <= 2.20.47 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-37205MEDIUMWordPress affiliate-toolkit plugin <= 3.4.4 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-25923MEDIUMWordPress Community by PeepSo plugin <= 6.2.7.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-32513MEDIUMWordPress Product Feed PRO for WooCommerce plugin <= 13.3.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-23760LOWCleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json andEPSS 0.4%CVE-2024-36127HIGHapko Exposure of HTTP basic auth credentials in log outputEPSS 0.4%CVE-2022-44587MEDIUMWordPress WP 2FA plugin <= 2.6.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2026-28987HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.4%CVE-2026-28943HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.4%CVE-2025-11008CRITICALCE21 Suite <= 2.3.1 - Unauthenticated Sensitive Information Exposure to Privilege EscalationEPSS 0.4%CVE-2025-66236HIGHApache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UIEPSS 0.4%CVE-2021-22533MEDIUMPossible Insertion of Sensitive Information into Log File VulnerabilityEPSS 0.4%