Falhas do tipo CWE-532

775 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2023-43261HIGHAn information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router componentsEPSS 59.3%CVE-2024-20440HIGHA vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vuEPSS 51.9%CVE-2024-9466HIGHExpedition: Cleartext Storage of Information Leads to Firewall Admin Credential DisclosureEPSS 12.9%CVE-2025-9985MEDIUMFeatured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log FileEPSS 11.1%CVE-2026-22778CRITICALvLLM leaks a heap address when PIL throws an errorEPSS 3.7%CVE-2012-0814MEDIUMThe auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command oEPSS 3.7%CVE-2017-7550A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. RemEPSS 3.6%CVE-2019-3888MEDIUMA vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because EPSS 3.4%CVE-2018-10855MEDIUMAnsible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used tEPSS 3.1%CVE-2021-34797Apache Geode project log file redaction of sensitive information vulnerabilityEPSS 2.9%CVE-2023-21492MEDIUMKernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.EPSS 2.6%KEVCVE-2024-48852MEDIUMInformation disclosuresEPSS 2.4%CVE-2021-32724CRITICALcheck-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attackEPSS 2.3%CVE-2013-4733HIGHThe web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 aEPSS 2.3%CVE-2018-10889MEDIUMA flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain EPSS 2.1%CVE-2025-14437HIGHHummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log FileEPSS 2.0%CVE-2025-68675HIGHApache Airflow: proxy credentials for various providers might leak in task logsEPSS 2.0%CVE-2025-24984MEDIUMWindows NTFS Information Disclosure VulnerabilityEPSS 2.0%KEVCVE-2023-22649HIGHRancher 'Audit Log' leaks sensitive informationEPSS 1.9%CVE-2019-1961MEDIUMCisco Enterprise NFV Infrastructure Software Web Portal Arbitrary File Read VulnerabilityEPSS 1.9%