Fallos del tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2023-44483Apache Santuario: Private Key disclosure in debug-log outputEPSS 1.2%CVE-2023-46215HIGHApache Airflow Celery provider, Apache Airflow: Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backendEPSS 1.2%CVE-2024-0716LOWByzoro Smart S150 Management Platform Backup File download.php information disclosureEPSS 1.2%CVE-2021-25009CorreosExpress <= 2.6.0 - Sensitive Information DisclosureEPSS 1.2%CVE-2026-24308MEDIUMApache ZooKeeper: Sensitive information disclosure in client configuration handlingEPSS 1.2%CVE-2021-21361MEDIUMSensitive information disclosure via log in com.bmuschko:gradle-vagrant-pluginEPSS 1.2%CVE-2019-13515OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.EPSS 1.2%CVE-2025-25002MEDIUMAzure Local Cluster Information Disclosure VulnerabilityEPSS 1.1%CVE-2022-31047MEDIUMInsertion of Sensitive Information into Log File in typo3/cms-coreEPSS 1.1%CVE-2022-24758HIGHInsertion of Sensitive Information into Log File affects Jupyter NotebookEPSS 1.1%CVE-2019-11292HIGHPivotal Ops Manager logs query parameters in tomcat access fileEPSS 1.1%CVE-2024-34706CRITICAL@valtimo/components exposes access token to form.ioEPSS 1.1%CVE-2020-11094MEDIUMPotential unauthorized access to stored request & session data when plugin is misconfigured in October CMS DebugbarEPSS 1.0%CVE-2020-3281MEDIUMCisco Digital Network Architecture Center Information Disclosure VulnerabilityEPSS 1.0%CVE-2019-11273LOWPKS Telemetry logs credentialsEPSS 1.0%CVE-2018-3827A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the reposEPSS 1.0%CVE-2020-11646MEDIUMGateManager Log Information Disclosure VulnerabilityEPSS 1.0%CVE-2025-31139MEDIUMIn JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build logEPSS 1.0%CVE-2025-46432MEDIUMIn JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logsEPSS 1.0%CVE-2021-22030In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) infoEPSS 1.0%