Falhas do tipo CWE-532

852 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-2092HIGHRemote site authentication secrets written to web logEPSS 0.3%CVE-2024-55578MEDIUMZammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.EPSS 0.3%CVE-2024-41824MEDIUMIn JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific casesEPSS 0.3%CVE-2024-29177LOWDell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive informatiEPSS 0.3%CVE-2026-14528HIGHIBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive informationEPSS 0.3%CVE-2025-8663HIGHInsertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain CredentialsEPSS 0.3%CVE-2024-29958HIGHEncryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node.EPSS 0.3%CVE-2026-1918MEDIUMIBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log fileEPSS 0.3%CVE-2021-3425A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfileEPSS 0.3%CVE-2019-11271MEDIUMBosh Deployment logs leak sensitive informationEPSS 0.3%CVE-2026-25826MEDIUMAn issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable filEPSS 0.3%CVE-2026-71845MEDIUMInsights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault()EPSS 0.3%CVE-2026-55785LOWfree5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKAEPSS 0.3%CVE-2024-24939LOWIn JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possibleEPSS 0.3%CVE-2025-7426CRITICALMINOVA TTA Information Disclosure and Credential ExposureEPSS 0.3%CVE-2022-43673MEDIUMWire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of EPSS 0.3%CVE-2026-88883HIGHRenovate before 44.14.4 TLS Private Key Log SanitisationEPSS 0.3%CVE-2025-7371MEDIUMOkta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows aEPSS 0.3%CVE-2025-30205HIGHkanidm-provision leaks provisioned admin credentials into the system logEPSS 0.3%CVE-2026-4957MEDIUMOpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log fileEPSS 0.3%