Fallos del tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2025-24389MEDIUMSMTP Password will be shown in cleartext on some SMTP errorsEPSS 0.1%CVE-2026-78627HIGHImproper Credential Protection in Okta Hyperdrive Integration Installer LoggingEPSS 0.1%CVE-2025-26332HIGHTechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. EPSS 0.1%CVE-2024-11165MEDIUMAn information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration reEPSS 0.1%CVE-2025-54781LOWHimmelblau leaks an Intune service access token in its logsEPSS 0.1%CVE-2025-30105HIGHDell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker wEPSS 0.1%CVE-2024-12057LOWUser credentials recorded in log filesEPSS 0.1%CVE-2025-5781MEDIUMInformation Exposure Vulnerability in Hitachi Configuration Manager, Hitachi Ops Center API Configuration ManagerEPSS 0.1%CVE-2026-0519MEDIUMInformation Disclosure in Secure Access Between 12.70 and 14.20EPSS 0.1%CVE-2026-78631MEDIUMImproper Restriction of Sensitive Information in Okta Hyperdrive Agent LoggingEPSS 0.1%CVE-2026-59326LOWHTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language ServerEPSS 0.1%CVE-2025-6392MEDIUMDaily Data Dump Collector logs database password in cleartext when running docker exec commands (CVE-2025-6392)EPSS 0.1%CVE-2026-80169LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of SensEPSS 0.1%CVE-2026-79966LOWCWE-532: Insertion of Sensitive Information into Log FileEPSS 0.1%CVE-2026-25193HIGHInsertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentiaEPSS 0.1%CVE-2025-4234LOWCortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of CredentialsEPSS 0.1%CVE-2025-14010MEDIUMAnsible-collection-community-general: ansible-collection-community-general: keycloak user module leaks credentials in verbose outputEPSS 0.1%CVE-2025-6587MEDIUMExposure of system environment variables in Docker Desktop diagnostic logsEPSS 0.1%CVE-2021-22518MEDIUMSensitive Information logging in NetIQ Identity Manager DriverEPSS 0.1%CVE-2026-44105MEDIUMCleartext password in logsEPSS 0.1%