Fallos del tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2026-32982HIGHOpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error LogsEPSS 0.4%CVE-2024-37270MEDIUMWordPress TrustedLogin Vendor plugin < 1.1.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-38321MEDIUMIBM Business Automation Workflow information disclosureEPSS 0.4%CVE-2025-57813MEDIUMInsertion of Sensitive Information into Log File in github.com/traPtitech/traQEPSS 0.4%CVE-2024-40636MEDIUMBasic Auth Credential Leakage to Logs After Fetch Registry Error in Steeltoe.Discovery.Eureka with Peer AwarenessEPSS 0.4%CVE-2026-87779HIGHApache Syncope: AES Secret Key disclosure via log outputEPSS 0.4%CVE-2026-54652HIGHFrigate viewer can read logs exposing admin and camera credentialsEPSS 0.4%CVE-2025-54064MEDIUMrucio-server, rucio-ui, and rucio-webui vulnerable to insertion of X-Rucio-Auth-Token in apache access logfilesEPSS 0.4%CVE-2026-41018MEDIUMApache Airflow Providers Elasticsearch: Elasticsearch task-log handler leaks credentials embedded in the host URLEPSS 0.4%CVE-2026-43826MEDIUMApache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URLEPSS 0.4%CVE-2020-15095MEDIUMSensitive information exposure through logs in npm cliEPSS 0.4%CVE-2024-47570MEDIUMAn insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all verEPSS 0.4%CVE-2025-53886MEDIUMDirectus doesn't redact tokens in Flow logsEPSS 0.4%CVE-2023-50951MEDIUMIBM QRadar Suite information disclosureEPSS 0.4%CVE-2023-32491MEDIUM Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user EPSS 0.4%CVE-2025-14432HIGHPoly Video - Sensitive Data Might Be Written to Log FileEPSS 0.4%CVE-2026-14948HIGHFrauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive Information into Log File via error log archivesEPSS 0.4%CVE-2025-24651MEDIUMWordPress WebToffee WP Backup and Migration plugin <= 1.5.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2022-27895MEDIUMA component in Foundry logging was found to be capturing sensitive information in logs.EPSS 0.4%CVE-2022-27896MEDIUMThe Foundry Code-Workbooks service was found to contain an issue leading to information disclosure.EPSS 0.4%