Fallos del tipo CWE-532

852 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2026-41185MEDIUMServiceAccount token disclosure via Azure IPAM CNI plugin logsEPSS 0.3%CVE-2026-66780MEDIUMSubmariner-operator: broker serviceaccount secret (token + ca) logged in full at trace verbosityEPSS 0.3%CVE-2024-38862MEDIUMSNMP and IMPI secrets written to audit logEPSS 0.3%CVE-2024-23840MEDIUM`goreleaser release --debug` shows secretsEPSS 0.3%CVE-2024-42407HIGHInsertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authentiEPSS 0.3%CVE-2024-55891LOWInformation Disclosure via Exception Handling/Logger in TYPO3EPSS 0.3%CVE-2026-2350MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.EPSS 0.3%CVE-2026-1292MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in Trends.EPSS 0.3%CVE-2026-81705HIGHopenssl-encrypt before 1.4.9 Password Cleartext Leak via DebugEPSS 0.3%CVE-2026-73457MEDIUMUnder certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.EPSS 0.3%CVE-2025-1075MEDIUMLDAP credentials logged to Apache error logEPSS 0.3%CVE-2023-38271MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%CVE-2025-62513MEDIUMOpenBao leaks HTTPRawBody in Audit LogsEPSS 0.3%CVE-2020-1624MEDIUMJunos OS Evolved: objmon logs may leak sensitive informationEPSS 0.3%CVE-2020-1623MEDIUMJunos OS Evolved: ev.ops file may leak sensitive informationEPSS 0.3%CVE-2020-37267HIGHRenovate 19.180.0 before 23.25.1 Token Leakage via LogsEPSS 0.3%CVE-2025-10645MEDIUMWP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via wf-licensing.logEPSS 0.3%CVE-2021-20180—A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature wEPSS 0.3%CVE-2019-25766HIGHRenovate before 19.38.7 Credential Exposure via Go ModulesEPSS 0.3%CVE-2025-4090MEDIUMLeaked library paths in Thunderbird for AndroidEPSS 0.3%