Falhas do tipo CWE-532

857 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2024-32051MEDIUMInsertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a networkEPSS 0.3%CVE-2026-20205HIGHSensitive Information Disclosure in ''_internal'' index in Splunk MCP Server appEPSS 0.3%CVE-2026-41219HIGHBIG-IP QKView vulnerabilityEPSS 0.3%CVE-2024-34715LOWPartial Password Exposure Vulnerability in Fides Webserver LogsEPSS 0.3%CVE-2026-87993HIGHConsul-template vulnerable to an information disclosure issue in error handlingEPSS 0.3%CVE-2024-44239MEDIUMAn information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7.1 and iPEPSS 0.3%CVE-2026-86501LOWIn JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.logEPSS 0.3%CVE-2023-46742MEDIUMCubeFS leaks users key in logsEPSS 0.3%CVE-2025-12940LOWCredentials recorded in logs in NETGEAR WAX610 and WAX610YEPSS 0.3%CVE-2024-8775MEDIUMAnsible-core: exposure of sensitive information in ansible vault files due to improper loggingEPSS 0.3%CVE-2026-92237MEDIUMInsertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier EPSS 0.3%CVE-2026-2605MEDIUMTanium addressed an insertion of sensitive information into log file vulnerability in TanOS.EPSS 0.3%CVE-2026-55221MEDIUMBoruta: OAuth credentials exposed in Boruta business logsEPSS 0.3%CVE-2026-65311MEDIUMMissing authentication for logging-configuration endpointEPSS 0.3%CVE-2024-3744MEDIUMKubernetes azure-file-csi-driver in versions before 1.29.4 and 1.30.1 discloses service account tokens in logsEPSS 0.3%CVE-2024-58269MEDIUMRancher exposes sensitive information through audit logsEPSS 0.3%CVE-2024-0006MEDIUMDB User Password Leak in Application LogEPSS 0.3%CVE-2026-25813HIGHPlaciPy Exposes Sensitive Data via Application LogsEPSS 0.3%CVE-2025-64650MEDIUMIBM Storage Defender - Resiliency Service Information DisclosureEPSS 0.3%CVE-2020-6653LOWSensitive date stored in logcat fileEPSS 0.3%