Fallos del tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados sensíveis (senhas, tokens, chaves criptográficas, PII) em arquivos de log que acabam acessíveis a usuários não autorizados. Isso expõe credenciais e informações críticas sem necessidade, transformando o log em vetor de ataque.

Ejemplo

Um serviço de autenticação que escreve no log: 'Usuário admin logou com senha: senhaForte123!' ou uma API que registra tokens JWT completos em caso de erro. Se alguém tiver acesso ao arquivo de log (via LFI, backup exposto ou permissões fracas), captura as credenciais.

Cómo mitigar

Nunca registre dados sensíveis: máscare ou omita senhas, tokens e chaves. Se precisar logar para debug, use aliases/hashes e remova antes de produção. Restrinja acesso aos arquivos de log (permissões Unix, encriptação) e implemente rotação/limpeza automática de logs antigos.

CVE-2024-2302MEDIUMEasy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information ExposureEPSS 0.6%CVE-2024-23686MEDIUMDependencyCheck Debug Mode Logging of NVD API KeyEPSS 0.6%CVE-2025-31213HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, mEPSS 0.6%CVE-2023-33001HIGHJenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the buildEPSS 0.6%CVE-2025-24457MEDIUMIn JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logsEPSS 0.6%CVE-2023-0436MEDIUMSecret logging may occur in debug mode of Atlas Operator EPSS 0.6%CVE-2018-3828Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exceptiEPSS 0.6%CVE-2020-11932LOWSubiquity server installer logged LUKS full disk encryption passwordEPSS 0.6%CVE-2025-59258MEDIUMWindows Active Directory Federation Services (ADFS) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-49923MEDIUMEnterprise Search Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2026-21222MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-6687MEDIUMElastic Agent Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2024-31259HIGHWordPress SearchIQ plugin <= 4.5 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.6%CVE-2021-39011MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2024-34550MEDIUMWordPress Dynamics 365 Integration plugin <= 1.3.17 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2022-2721HIGHIn affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plainEPSS 0.6%CVE-2024-35196LOWSlack integration leaks sensitive information in logs in SentryEPSS 0.6%CVE-2025-31479HIGHcanonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception outputEPSS 0.6%CVE-2020-14330MEDIUMAn Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content aEPSS 0.6%CVE-2022-23716MEDIUMA flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in dEPSS 0.6%