Fallos del tipo CWE-532

857 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2023-1786MEDIUMsensitive data exposure in cloud-init logsEPSS 0.3%CVE-2026-29184LOW@backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction BypassEPSS 0.3%CVE-2020-26199MEDIUMDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentiaEPSS 0.3%CVE-2026-24762MEDIUMRustFS Logs Sensitive Credentials in PlaintextEPSS 0.3%CVE-2022-35202MEDIUMA security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the EPSS 0.3%CVE-2026-4901MEDIUMInsertion of Sesitive Information into Log File in AlanWeb SCADAEPSS 0.3%CVE-2022-31186LOWLeakage of excessive information into log in next-authEPSS 0.3%CVE-2026-41495MEDIUMn8n-MCP Logs Sensitive Request Data on Unauthorized /mcp RequestsEPSS 0.3%CVE-2025-43426MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may beEPSS 0.3%CVE-2019-18244—In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts arEPSS 0.3%CVE-2023-28630MEDIUMSensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocdEPSS 0.3%CVE-2024-27154MEDIUMPasswords are stored in clear-text logs.EPSS 0.3%CVE-2025-41690HIGHEndress+Hauser: Proline 10 Maintenance credentials may be exposed under certain conditionsEPSS 0.3%CVE-2026-42282MEDIUMn8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP modeEPSS 0.3%CVE-2021-36340HIGHDell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulneEPSS 0.3%CVE-2021-21597HIGHDell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical acceEPSS 0.3%CVE-2021-21598LOWDell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with pEPSS 0.3%CVE-2021-21558HIGHDell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator EPSS 0.3%CVE-2021-3684—A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plainteEPSS 0.2%CVE-2025-13611LOWInsertion of Sensitive Information into Log File in GitLabEPSS 0.2%