Falhas do tipo CWE-532

852 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2026-41185MEDIUMServiceAccount token disclosure via Azure IPAM CNI plugin logsEPSS 0.3%CVE-2026-66780MEDIUMSubmariner-operator: broker serviceaccount secret (token + ca) logged in full at trace verbosityEPSS 0.3%CVE-2024-38862MEDIUMSNMP and IMPI secrets written to audit logEPSS 0.3%CVE-2024-23840MEDIUM`goreleaser release --debug` shows secretsEPSS 0.3%CVE-2024-42407HIGHInsertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authentiEPSS 0.3%CVE-2024-55891LOWInformation Disclosure via Exception Handling/Logger in TYPO3EPSS 0.3%CVE-2026-2350MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.EPSS 0.3%CVE-2026-1292MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in Trends.EPSS 0.3%CVE-2026-81705HIGHopenssl-encrypt before 1.4.9 Password Cleartext Leak via DebugEPSS 0.3%CVE-2026-73457MEDIUMUnder certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.EPSS 0.3%CVE-2025-1075MEDIUMLDAP credentials logged to Apache error logEPSS 0.3%CVE-2023-38271MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%CVE-2025-62513MEDIUMOpenBao leaks HTTPRawBody in Audit LogsEPSS 0.3%CVE-2020-1624MEDIUMJunos OS Evolved: objmon logs may leak sensitive informationEPSS 0.3%CVE-2020-1623MEDIUMJunos OS Evolved: ev.ops file may leak sensitive informationEPSS 0.3%CVE-2020-37267HIGHRenovate 19.180.0 before 23.25.1 Token Leakage via LogsEPSS 0.3%CVE-2025-10645MEDIUMWP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via wf-licensing.logEPSS 0.3%CVE-2021-20180A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature wEPSS 0.3%CVE-2019-25766HIGHRenovate before 19.38.7 Credential Exposure via Go ModulesEPSS 0.3%CVE-2025-4090MEDIUMLeaked library paths in Thunderbird for AndroidEPSS 0.3%