Fallos del tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2025-13321LOWMattermost Desktop App logging sensitive information and fails to clear data on server deletionEPSS 0.1%CVE-2025-27496LOWSnowflake JDBC Driver client-side encryption key in DEBUG logsEPSS 0.1%CVE-2025-46329LOWSnowflake Connector for C/C++ inserts client-side encryption key in DEBUG logsEPSS 0.1%CVE-2021-21508MEDIUMDell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit thisEPSS 0.1%CVE-2026-1495MEDIUMInsertion of Sensitive Information into Log File vulnerability in AVEVA PI to CONNECT AgentEPSS 0.1%CVE-2023-50301LOWIBM Transformation Extender Advanced information disclosureEPSS 0.1%CVE-2022-45098MEDIUM Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticateEPSS 0.1%CVE-2025-68919MEDIUMFujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenancEPSS 0.1%CVE-2026-46467MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.1%CVE-2026-19502MEDIUMInsufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLIEPSS 0.1%CVE-2025-36133MEDIUMIBM App Connect Enterprise information disclosureEPSS 0.1%CVE-2024-29955MEDIUMInsertion of Sensitive Information into Brocade SANnav Log FileEPSS 0.1%CVE-2026-0936MEDIUMInsertion of Sensitive Information into LogfileEPSS 0.1%CVE-2026-16689MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.1%CVE-2026-19649MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.1%CVE-2024-11604HIGHInsertion of Sensitive Information into Log FileEPSS 0.1%CVE-2025-12996MEDIUMMedtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errorEPSS 0.1%CVE-2025-13755MEDIUMIBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase bucketsEPSS 0.1%CVE-2025-3456LOWOn affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-cEPSS 0.1%CVE-2026-0267MEDIUMGlobalProtect App: Information Exposure Vulnerability on macOSEPSS 0.1%