Falhas do tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2026-34487HIGHApache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer tokenEPSS 0.4%CVE-2024-30523MEDIUMWordPress Paid Memberships Pro – Mailchimp Add On plugin <= 2.3.4 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-33922MEDIUMWordPress WP Media Cleaner plugin <= 6.7.2 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2023-49921MEDIUMAn issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw cEPSS 0.4%CVE-2025-62232HIGHApache APISIX: basic-auth logs plaintext credentials at info levelEPSS 0.4%CVE-2024-22339MEDIUMIBM UrbanCode Deploy information disclosureEPSS 0.4%CVE-2024-25923MEDIUMWordPress Community by PeepSo plugin <= 6.2.7.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-32686MEDIUMWordPress Backup Migration plugin <= 1.4.3 - Sensitive Data Exposure via Log vulnerabilityEPSS 0.4%CVE-2024-22138MEDIUMWordPress Seraphinite Accelerator plugin <= 2.20.47 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-37205MEDIUMWordPress affiliate-toolkit plugin <= 3.4.4 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-32513MEDIUMWordPress Product Feed PRO for WooCommerce plugin <= 13.3.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-23760LOWCleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json andEPSS 0.4%CVE-2024-36127HIGHapko Exposure of HTTP basic auth credentials in log outputEPSS 0.4%CVE-2022-44587MEDIUMWordPress WP 2FA plugin <= 2.6.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2026-22038HIGHAutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration BlocksEPSS 0.4%CVE-2026-28943HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.4%CVE-2026-28987HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.4%CVE-2025-11008CRITICALCE21 Suite <= 2.3.1 - Unauthenticated Sensitive Information Exposure to Privilege EscalationEPSS 0.4%CVE-2025-66236HIGHApache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UIEPSS 0.4%CVE-2021-22533MEDIUMPossible Insertion of Sensitive Information into Log File VulnerabilityEPSS 0.4%