Falhas do tipo CWE-532

851 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2024-32757MEDIUMAmerican Dynamics Illustra Essentials Gen 4 - Linux Credential LeakEPSS 0.4%CVE-2026-65589MEDIUMn8n before 1.123.64 Credential Exposure via LLM Node Execution DataEPSS 0.4%CVE-2024-37930MEDIUMWordPress SmartMag theme < 10.1.0 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-43990MEDIUMWordPress Masterstudy LMS Starter theme <= 1.1.8 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2022-26322MEDIUMPossible Insertion of Sensitive Information into Log File Vulnerability in Identity ManagerEPSS 0.4%CVE-2026-34164MEDIUMValtimo: Sensitive data exposure through inbox message logging in InboxHandlingServiceEPSS 0.4%CVE-2024-5908MEDIUMGlobalProtect App: Encrypted Credential Exposure via Log FilesEPSS 0.4%CVE-2024-32811MEDIUMWordPress USPS Shipping for WooCommerce – Live Rates plugin <= 1.9.4 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2025-20329MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-46171MEDIUMIBM DS8900F information disclosureEPSS 0.4%CVE-2025-27555MEDIUMApache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cliEPSS 0.4%CVE-2025-31514LOWA insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS EPSS 0.4%CVE-2026-65945MEDIUMApache Ranger: Logs contain replayable JWT bearer tokensEPSS 0.4%CVE-2024-6104MEDIUMgo-retryablehttp can leak basic auth credentials to log filesEPSS 0.4%CVE-2022-40979MEDIUMIn JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executableEPSS 0.4%CVE-2026-68969MEDIUMApache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartextEPSS 0.4%CVE-2019-5634MEDIUMHickory Smart Lock Insecure Logging on AndroidEPSS 0.4%CVE-2025-25013MEDIUMElastic Defend Insertion of Sensitive Information into Log FilesEPSS 0.4%CVE-2024-13416MEDIUMUsing API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has relEPSS 0.4%CVE-2023-28441HIGHsmartCARS 3 Password Stored as plain text in Error LogEPSS 0.4%