Fallos del tipo CWE-532

852 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2026-35185HIGHHAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addressesEPSS 0.4%CVE-2026-92918HIGHadmin3 through 3.0.0 Session Token Disclosure via Audit LogEPSS 0.4%CVE-2018-1075MEDIUMovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run andEPSS 0.4%CVE-2024-9453MEDIUMJenkins-image: sensitive data disclosure when using openshift jenkins imageEPSS 0.4%CVE-2024-49816MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.4%CVE-2024-0935MEDIUMInsertion of Sensitive Information into Log File vulnerabilities affecting DELMIA Apriso Release 2019 through Release 2024EPSS 0.4%CVE-2024-12226MEDIUMIn affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in cleEPSS 0.4%CVE-2021-20191—A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log featureEPSS 0.3%CVE-2023-46668MEDIUMElastic Endpoint Insertion of Sensitive Information into Log FileEPSS 0.3%CVE-2026-78174CRITICALWatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsEPSS 0.3%CVE-2019-10194MEDIUMSensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. PasswordEPSS 0.3%CVE-2023-4688MEDIUMSensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433.EPSS 0.3%CVE-2024-34798MEDIUMWordPress Debug Log – Manger Tool plugin <= 1.4.5 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-23374HIGHDell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information EPSS 0.3%CVE-2020-2048LOWPAN-OS: System proxy passwords may be logged in clear text while viewing system stateEPSS 0.3%CVE-2023-46175MEDIUMIBM Cloud Pak for Multicloud Management information disclosureEPSS 0.3%CVE-2025-62879MEDIUMRancher Backup Operator pod's logs leak S3 tokensEPSS 0.3%CVE-2022-4311MEDIUM An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with EPSS 0.3%CVE-2021-20178—A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature wEPSS 0.3%CVE-2025-15332MEDIUMTanium addressed an information disclosure vulnerability in Threat Response.EPSS 0.3%