Fallos del tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2025-6624LOWVersions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debugEPSS 0.2%CVE-2026-20165MEDIUMSensitive Information Disclosure in MongoClient logging channel in Splunk EnterpriseEPSS 0.2%CVE-2025-49009MEDIUMPara Inserts Sensitive Information into Log File for Facebook authenticationEPSS 0.2%CVE-2025-48955MEDIUMPara Server Logs Sensitive InformationEPSS 0.2%CVE-2023-6833MEDIUMInformation Exposure Vulnerability in Hitachi Ops Center AdministratorEPSS 0.2%CVE-2023-27502LOWInsertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2316.5.1.2 may allow EPSS 0.2%CVE-2026-44969LOWdbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is EnabledEPSS 0.2%CVE-2024-0912HIGHCCURE passwords exposed to administratorsEPSS 0.2%CVE-2024-40096LOWThe com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.EPSS 0.2%CVE-2023-30430MEDIUMIBM Security Verify Access information disclosureEPSS 0.2%CVE-2024-40679MEDIUMIBM Db2 information disclosureEPSS 0.2%CVE-2026-28868MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, mEPSS 0.2%CVE-2023-25604MEDIUMAn insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext pEPSS 0.2%CVE-2026-0637MEDIUMSensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 ProductsEPSS 0.2%CVE-2025-2002MEDIUMCWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials whEPSS 0.2%CVE-2026-44479MEDIUMVercel: Non-interactive mode includes CLI arguments in suggested command outputEPSS 0.2%CVE-2023-3335MEDIUMInformation Exposure Vulnerability in Hitachi Ops Center AdministratorEPSS 0.2%CVE-2026-41004MEDIUMWhen enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.EPSS 0.2%CVE-2025-23413MEDIUMBIG-IP Next Central Manager vulnerabilityEPSS 0.2%CVE-2026-11819MEDIUMCommunity.general: community.general keyring_info — os keyring passphrase returned in plaintextEPSS 0.2%