Falhas do tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2026-64800LOWIn JetBrains GoLand before 2026.2 sensitive configuration values written to log files by defaultEPSS 0.5%CVE-2023-38733MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.5%CVE-2024-39460MEDIUMJenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL inEPSS 0.5%CVE-2025-1296MEDIUMNomad Exposes Sensitive Workload Identity and Client Secret Token in Audit LogsEPSS 0.5%CVE-2024-41978HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.5%CVE-2026-20239HIGHSensitive Information Disclosure through Log Files in Splunk EnterpriseEPSS 0.5%CVE-2022-29928MEDIUMIn JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possibleEPSS 0.5%CVE-2025-31199MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS SonomEPSS 0.5%CVE-2024-31254LOWWordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2025-11248LOWSensitive Information LoggedEPSS 0.5%CVE-2026-82434CRITICALApache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to LogsEPSS 0.5%CVE-2023-51490MEDIUMWordPress Defender Security Plugin <= 4.1.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2023-51408MEDIUMWordPress WP Optin Wheel Plugin <= 1.4.3 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2023-51508MEDIUMWordPress Database Cleaner Plugin <= 0.9.8 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-50316MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-46231HIGHSession Token Disclosure to Internal Log Files in Splunk Add-on BuilderEPSS 0.5%CVE-2024-29959HIGHBrocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support saveEPSS 0.5%CVE-2023-20207MEDIUMA vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive iEPSS 0.5%CVE-2022-33187MEDIUMBrocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logsEPSS 0.5%CVE-2023-22481MEDIUMSensitive information exposure in the logs of greader API in FreshRSSEPSS 0.5%