Falhas do tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-20231HIGHSensitive Information Disclosure in Splunk Secure Gateway AppEPSS 0.5%CVE-2023-41308Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.EPSS 0.5%CVE-2020-8563MEDIUMSecret leaks in logs for vSphere Provider kube-controller-managerEPSS 0.5%CVE-2023-6746HIGHSensitive Information in Log File in GitHub Enterprise Server EPSS 0.5%CVE-2020-1753MEDIUMA security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all EPSS 0.5%CVE-2024-31298MEDIUMWordPress User Spam Remover plugin <= 1.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-31247MEDIUMWordPress FG Drupal to WordPress plugin <= 3.70.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2024-31249MEDIUMWordPress Subscribe To Comments Reloaded plugin <= 220725 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-13818MEDIUMRegistration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction <= 3.8.4 - Sensitive Information Exposure via Log FilesEPSS 0.5%CVE-2025-22275CRITICALiTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by readinEPSS 0.5%CVE-2026-41184MEDIUMServiceAccount token disclosure via install-cni container logsEPSS 0.5%CVE-2024-34527HIGHspaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged.EPSS 0.5%CVE-2023-26207LOWAn insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.1EPSS 0.5%CVE-2023-38067MEDIUMIn JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2023-38064MEDIUMIn JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2023-47131HIGHThe N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.EPSS 0.5%CVE-2024-3165MEDIUMDatabase Credential Exposure in the LogsEPSS 0.5%CVE-2024-22352MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.5%CVE-2024-37286MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.5%CVE-2025-31788MEDIUMWordPress AIO Performance Profiler, Monitor, Optimize, Compress & Debug plugin <= 1.3 - Sensitive Data Exposure vulnerabilityEPSS 0.5%