Falhas do tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2026-32982HIGHOpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error LogsEPSS 0.4%CVE-2024-37270MEDIUMWordPress TrustedLogin Vendor plugin < 1.1.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-38321MEDIUMIBM Business Automation Workflow information disclosureEPSS 0.4%CVE-2025-57813MEDIUMInsertion of Sensitive Information into Log File in github.com/traPtitech/traQEPSS 0.4%CVE-2024-40636MEDIUMBasic Auth Credential Leakage to Logs After Fetch Registry Error in Steeltoe.Discovery.Eureka with Peer AwarenessEPSS 0.4%CVE-2026-87779HIGHApache Syncope: AES Secret Key disclosure via log outputEPSS 0.4%CVE-2026-54652HIGHFrigate viewer can read logs exposing admin and camera credentialsEPSS 0.4%CVE-2025-54064MEDIUMrucio-server, rucio-ui, and rucio-webui vulnerable to insertion of X-Rucio-Auth-Token in apache access logfilesEPSS 0.4%CVE-2026-41018MEDIUMApache Airflow Providers Elasticsearch: Elasticsearch task-log handler leaks credentials embedded in the host URLEPSS 0.4%CVE-2026-43826MEDIUMApache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URLEPSS 0.4%CVE-2020-15095MEDIUMSensitive information exposure through logs in npm cliEPSS 0.4%CVE-2024-47570MEDIUMAn insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all verEPSS 0.4%CVE-2025-53886MEDIUMDirectus doesn't redact tokens in Flow logsEPSS 0.4%CVE-2023-50951MEDIUMIBM QRadar Suite information disclosureEPSS 0.4%CVE-2023-32491MEDIUM Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user EPSS 0.4%CVE-2025-14432HIGHPoly Video - Sensitive Data Might Be Written to Log FileEPSS 0.4%CVE-2026-14948HIGHFrauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive Information into Log File via error log archivesEPSS 0.4%CVE-2025-24651MEDIUMWordPress WebToffee WP Backup and Migration plugin <= 1.5.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2022-27895MEDIUMA component in Foundry logging was found to be capturing sensitive information in logs.EPSS 0.4%CVE-2022-27896MEDIUMThe Foundry Code-Workbooks service was found to contain an issue leading to information disclosure.EPSS 0.4%