Falhas do tipo CWE-532

852 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-5464MEDIUMInsertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker toEPSS 0.3%CVE-2025-5463MEDIUMInsertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version EPSS 0.3%CVE-2023-28443MEDIUMdirectus vulnerable to Insertion of Sensitive Information into Log FileEPSS 0.3%CVE-2025-11504HIGHQuickcreator – AI Blog Writer 0.0.9 - 0.1.17 - Unauthenticated API Key ExposureEPSS 0.3%CVE-2024-47822MEDIUMDirectus inserts access token from query string into logsEPSS 0.3%CVE-2025-54319MEDIUMAn issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive inforEPSS 0.3%CVE-2019-18576MEDIUMDell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local fEPSS 0.3%CVE-2026-40945HIGHOxia: Bearer token exposed in debug log messages on authentication failureEPSS 0.3%CVE-2024-7586MEDIUMInsertion of Sensitive Information into Log File in GitLabEPSS 0.3%CVE-2019-19756HIGHAn internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updatesEPSS 0.3%CVE-2025-34188HIGHVasion Print (formerly PrinterLogic) Local Log Disclosure of Cleartext SessionsEPSS 0.3%CVE-2025-52893MEDIUMOpenBao May Leak Sensitive Information in Logs When Processing Malformed DataEPSS 0.3%CVE-2023-42937MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watEPSS 0.3%CVE-2023-28351LOWAn issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student applicatiEPSS 0.3%CVE-2024-40585MEDIUMAn insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, versioEPSS 0.3%CVE-2026-56457MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive informationEPSS 0.3%CVE-2024-29957HIGHEncryption key is stored in the DR log filesEPSS 0.3%CVE-2026-85174HIGHSiYuan before v3.8.2 API Token Exposure via Log FileEPSS 0.3%CVE-2023-40425MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14, macOS Monterey 1EPSS 0.3%CVE-2025-2092HIGHRemote site authentication secrets written to web logEPSS 0.3%