Fallos del tipo CWE-532

852 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2025-2092HIGHRemote site authentication secrets written to web logEPSS 0.3%CVE-2024-55578MEDIUMZammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.EPSS 0.3%CVE-2024-41824MEDIUMIn JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific casesEPSS 0.3%CVE-2024-29177LOWDell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive informatiEPSS 0.3%CVE-2026-14528HIGHIBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive informationEPSS 0.3%CVE-2025-8663HIGHInsertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain CredentialsEPSS 0.3%CVE-2024-29958HIGHEncryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node.EPSS 0.3%CVE-2026-1918MEDIUMIBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log fileEPSS 0.3%CVE-2021-3425—A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfileEPSS 0.3%CVE-2019-11271MEDIUMBosh Deployment logs leak sensitive informationEPSS 0.3%CVE-2026-25826MEDIUMAn issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable filEPSS 0.3%CVE-2026-71845MEDIUMInsights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault()EPSS 0.3%CVE-2026-55785LOWfree5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKAEPSS 0.3%CVE-2024-24939LOWIn JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possibleEPSS 0.3%CVE-2025-7426CRITICALMINOVA TTA Information Disclosure and Credential ExposureEPSS 0.3%CVE-2022-43673MEDIUMWire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of EPSS 0.3%CVE-2026-88883HIGHRenovate before 44.14.4 TLS Private Key Log SanitisationEPSS 0.3%CVE-2025-7371MEDIUMOkta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows aEPSS 0.3%CVE-2025-30205HIGHkanidm-provision leaks provisioned admin credentials into the system logEPSS 0.3%CVE-2026-4957MEDIUMOpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log fileEPSS 0.3%