Fallos del tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2021-21601HIGHDell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CISEPSS 0.2%CVE-2021-21546HIGHDell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vulnerability. A local lEPSS 0.2%CVE-2021-32801MEDIUMExceptions may have logged Encryption-at-Rest key content in Nextcloud serverEPSS 0.2%CVE-2025-6711MEDIUMIncomplete Redaction of Sensitive Information in MongoDB Server LogsEPSS 0.2%CVE-2026-50205HIGHPlaintext Log Credential LeakageEPSS 0.2%CVE-2026-86049HIGHJupyter Server: 5xx request logging leaks token-bearing Referer header valuesEPSS 0.2%CVE-2023-22447LOWInsertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a prEPSS 0.2%CVE-2025-24145LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS SEPSS 0.2%CVE-2025-46777LOWA insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 EPSS 0.2%CVE-2024-24272HIGHAn issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked EPSS 0.2%CVE-2025-6391HIGHJSON Web Token (JWT) Exposure in Log FilesEPSS 0.2%CVE-2022-2084MEDIUMsensitive data exposure in cloud-init logsEPSS 0.2%CVE-2026-32598MEDIUMOneUptime: Password Reset Token Logged at INFO LevelEPSS 0.2%CVE-2022-27888MEDIUMThe Foundry Issues service was found to be logging in a manner that captured session tokens.EPSS 0.2%CVE-2022-31239MEDIUMDell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerabilityEPSS 0.2%CVE-2026-12947HIGHIBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodesEPSS 0.2%CVE-2020-10052—A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data,EPSS 0.2%CVE-2025-66411HIGHCoder logged sensitive objects unsanitizedEPSS 0.2%CVE-2024-5557MEDIUMCWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attackeEPSS 0.2%CVE-2021-36318MEDIUMDell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentiaEPSS 0.2%