Falhas do tipo CWE-117

121 resultados

Injeção em logs (Log Injection)

O software escreve dados não sanitizados nos logs, permitindo que um atacante injete conteúdo malicioso (quebras de linha, caracteres de controle, formatação falsa) que pode ser interpretado como eventos legítimos, mascarar atividades suspeitas ou enganar ferramentas de monitoramento.

Exemplo

Um servidor web registra a URL solicitada diretamente no log sem filtrar quebras de linha. Um atacante envia requisição com payload como `/page?id=123%0aAdmin login failed`, que escreve nos logs como se fosse dois eventos separados, ocultando a atividade real ou imitando um acesso autorizado.

Como mitigar

Sanitize todos os dados antes de escrever em logs: remova ou escape caracteres de controle (\n, \r, \0), use formatação estruturada (JSON, syslog) em vez de concatenação de strings, e implemente validação rigorosa de entrada. Ferramentas de SIEM devem também rejeitar logs com estrutura inesperada.

CVE-2024-22356MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS information disclosureEPSS 0.5%CVE-2024-0095MEDIUMCVEEPSS 0.5%CVE-2024-8297MEDIUMkitsada8621 Digital Library Management System jwt_refresh_token_middleware.go JwtRefreshAuth neutralization for logsEPSS 0.5%CVE-2026-86522MEDIUMLog injection via an unescaped password reset identity in AshAuthenticationEPSS 0.5%CVE-2019-14846HIGHIn Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG EPSS 0.5%CVE-2024-52962MEDIUMAn Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, versioEPSS 0.5%CVE-2024-12580MEDIUMLogs Debug Injection in danny-avila/librechatEPSS 0.5%CVE-2024-9026LOWPHP-FPM logs from children may be alteredEPSS 0.5%CVE-2024-8334MEDIUMmaster-nan Sweet-CMS log.go LogHandler neutralization for logsEPSS 0.5%CVE-2023-46713MEDIUMAn improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may alEPSS 0.5%CVE-2023-36924MEDIUMLog Injection vulnerability in SAP ERP Defense Forces and Public SecurityEPSS 0.5%CVE-2023-31405MEDIUMLog Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)EPSS 0.4%CVE-2024-31845MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs.EPSS 0.4%CVE-2023-37275LOWSystem logs spoofable in Auto-GPT via ANSI control sequencesEPSS 0.4%CVE-2026-10745HIGHImproper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log InjectioEPSS 0.4%CVE-2024-32474HIGHSentry's superuser cleartext password leaked in logsEPSS 0.4%CVE-2019-14858HIGHA vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub paramEPSS 0.4%CVE-2023-0595MEDIUMA CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious pEPSS 0.4%CVE-2020-14332MEDIUMA flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensEPSS 0.4%CVE-2023-6002MEDIUMLog InjectionEPSS 0.4%