Falhas do tipo CWE-532

852 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2026-35185HIGHHAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addressesEPSS 0.4%CVE-2026-92918HIGHadmin3 through 3.0.0 Session Token Disclosure via Audit LogEPSS 0.4%CVE-2018-1075MEDIUMovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run andEPSS 0.4%CVE-2024-9453MEDIUMJenkins-image: sensitive data disclosure when using openshift jenkins imageEPSS 0.4%CVE-2024-49816MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.4%CVE-2024-0935MEDIUMInsertion of Sensitive Information into Log File vulnerabilities affecting DELMIA Apriso Release 2019 through Release 2024EPSS 0.4%CVE-2024-12226MEDIUMIn affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in cleEPSS 0.4%CVE-2021-20191A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log featureEPSS 0.3%CVE-2023-46668MEDIUMElastic Endpoint Insertion of Sensitive Information into Log FileEPSS 0.3%CVE-2026-78174CRITICALWatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsEPSS 0.3%CVE-2019-10194MEDIUMSensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. PasswordEPSS 0.3%CVE-2023-4688MEDIUMSensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433.EPSS 0.3%CVE-2024-34798MEDIUMWordPress Debug Log – Manger Tool plugin <= 1.4.5 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-23374HIGHDell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information EPSS 0.3%CVE-2020-2048LOWPAN-OS: System proxy passwords may be logged in clear text while viewing system stateEPSS 0.3%CVE-2023-46175MEDIUMIBM Cloud Pak for Multicloud Management information disclosureEPSS 0.3%CVE-2025-62879MEDIUMRancher Backup Operator pod's logs leak S3 tokensEPSS 0.3%CVE-2022-4311MEDIUM An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with EPSS 0.3%CVE-2021-20178A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature wEPSS 0.3%CVE-2025-15332MEDIUMTanium addressed an information disclosure vulnerability in Threat Response.EPSS 0.3%