Fallos del tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2023-31422CRITICALKibana Insertion of Sensitive Information into Log FileEPSS 0.8%CVE-2022-43936MEDIUMBrocade Fabric OS switch passwords when debugging is enabledEPSS 0.8%CVE-2021-37709MEDIUMInsecure direct object reference of log files of the Import/Export featureEPSS 0.8%CVE-2021-23046On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from AcceEPSS 0.8%CVE-2025-24169HIGHA logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be aEPSS 0.8%CVE-2024-0831MEDIUMVault May Expose Sensitive Information When Configuring An Audit Log DeviceEPSS 0.8%CVE-2022-28859MEDIUMOn F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-iEPSS 0.8%CVE-2022-0338MEDIUMInsertion of Sensitive Information into Log File in delgan/loguruEPSS 0.8%CVE-2024-27784HIGHMultiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may alloEPSS 0.8%CVE-2019-14885MEDIUMA flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security aEPSS 0.7%CVE-2026-31987HIGHApache Airflow: JWT token appearing in logsEPSS 0.7%CVE-2020-3447MEDIUMCisco Email Security Appliance and Cisco Content Security Management Appliance Information Disclosure VulnerabilityEPSS 0.7%CVE-2024-52067MEDIUMApache NiFi: Potential Insertion of Sensitive Parameter Values in Debug LogEPSS 0.7%CVE-2020-2044LOWPAN-OS: Passwords may be logged in clear text while storing operational command (op command) historyEPSS 0.7%CVE-2020-2043LOWPAN-OS: Passwords may be logged in clear text when using after-change-detail custom syslog field for config logsEPSS 0.7%CVE-2026-20818MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-3902MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5EPSS 0.7%CVE-2023-3993MEDIUMInsertion of Sensitive Information into Log File in GitLabEPSS 0.7%CVE-2025-26864HIGHApache IoTDB: Exposure of Sensitive Information in IoTDB OpenID AuthenticationEPSS 0.7%CVE-2025-26795HIGHApache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driverEPSS 0.7%