Fallos del tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2026-28923HIGHA logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26EPSS 0.2%CVE-2026-47234MEDIUMAdmidio writes session IDs and auto-login cookie values to application logsEPSS 0.2%CVE-2026-9735MEDIUMKeyfile contents are in MongoDB Server logsEPSS 0.2%CVE-2023-22573HIGHDell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privilegEPSS 0.2%CVE-2023-6814MEDIUMInformation Exposure Vulnerability in Cosminexus Component ContainerEPSS 0.2%CVE-2023-41253MEDIUMBIG-IP DNS TSIG Key vulnerabilityEPSS 0.2%CVE-2023-43485MEDIUMBIGIP and BIG-IQ TACACS+ audit log VulnerabilityEPSS 0.2%CVE-2023-45241MEDIUMSensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows)EPSS 0.2%CVE-2025-1696MEDIUMExposure of Proxy Credentials in Docker Desktop LogsEPSS 0.2%CVE-2026-75057MEDIUMIn JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE logEPSS 0.2%CVE-2026-59302LOWPotential for logging sensitive data in Spring Cloud StreamEPSS 0.2%CVE-2024-2877MEDIUMVault Enterprise Leaks Sensitive HTTP Request Headers in the Audit Log When Deployed With a Performance Standby NodeEPSS 0.2%CVE-2025-8864MEDIUMShared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logsEPSS 0.2%CVE-2023-40694MEDIUMIBM Watson CP4D Data Stores information disclosureEPSS 0.2%CVE-2021-3034MEDIUMCortex XSOAR: Secrets for SAML single sign-on (SSO) integration may be logged in system logsEPSS 0.2%CVE-2025-36050MEDIUMIBM QRadar SIEM information disclosureEPSS 0.2%CVE-2025-23261MEDIUMNVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentEPSS 0.2%CVE-2025-43508MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive EPSS 0.2%CVE-2026-93982MEDIUMOpenPanel MCP Authentication Token in Query Parameter Logged PlaintextEPSS 0.2%CVE-2025-6624LOWVersions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debugEPSS 0.2%