Fallos del tipo CWE-532

857 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2021-3036MEDIUMPAN-OS: Administrator secrets are logged in web server logs when using the PAN-OS XML API incorrectlyEPSS 0.2%CVE-2024-30151HIGHHCL BigFix Service Management (SM) is susceptible to Broken Access Control VulnerabilityEPSS 0.2%CVE-2025-37727MEDIUMElasticsearch Insertion of sensitive information in log fileEPSS 0.2%CVE-2021-21561HIGHDell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIVEPSS 0.2%CVE-2024-51752LOWRefresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-nextjsEPSS 0.2%CVE-2020-7322MEDIUMExposure of Sensitive Information in ENS for WindowsEPSS 0.2%CVE-2021-41808LOWIn M-Files Server product with versions before 21.11.10775.0, enabling logging of federated authentication would write sensitive information to event logs.EPSS 0.2%CVE-2026-20708MEDIUMInsertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an infoEPSS 0.2%CVE-2021-26908LOWAutomox Agent Sensitive Log Information DisclosureEPSS 0.2%CVE-2026-44052HIGHLDAP simple-bind password exposure in log outputEPSS 0.2%CVE-2024-40791LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 EPSS 0.2%CVE-2025-36599MEDIUMDell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privEPSS 0.2%CVE-2025-55285LOW@backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`EPSS 0.2%CVE-2021-36289HIGHDell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may EPSS 0.2%CVE-2026-7824MEDIUMPaperCut Hive (Ricoh): Plain text password in logsEPSS 0.2%CVE-2025-70040MEDIUMAn issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allEPSS 0.2%CVE-2021-1442HIGHCisco IOS XE Software Plug-and-Play Privilege Escalation VulnerabilityEPSS 0.2%CVE-2021-44234—SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attackerEPSS 0.2%CVE-2023-31417MEDIUMElasticsearch Insertion of sensitive information in audit logsEPSS 0.2%CVE-2021-40364MEDIUMA vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 VEPSS 0.2%