Falhas do tipo CWE-532

857 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2023-1786MEDIUMsensitive data exposure in cloud-init logsEPSS 0.3%CVE-2026-29184LOW@backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction BypassEPSS 0.3%CVE-2020-26199MEDIUMDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentiaEPSS 0.3%CVE-2026-24762MEDIUMRustFS Logs Sensitive Credentials in PlaintextEPSS 0.3%CVE-2022-35202MEDIUMA security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the EPSS 0.3%CVE-2026-4901MEDIUMInsertion of Sesitive Information into Log File in AlanWeb SCADAEPSS 0.3%CVE-2022-31186LOWLeakage of excessive information into log in next-authEPSS 0.3%CVE-2026-41495MEDIUMn8n-MCP Logs Sensitive Request Data on Unauthorized /mcp RequestsEPSS 0.3%CVE-2025-43426MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may beEPSS 0.3%CVE-2019-18244—In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts arEPSS 0.3%CVE-2023-28630MEDIUMSensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocdEPSS 0.3%CVE-2024-27154MEDIUMPasswords are stored in clear-text logs.EPSS 0.3%CVE-2025-41690HIGHEndress+Hauser: Proline 10 Maintenance credentials may be exposed under certain conditionsEPSS 0.3%CVE-2026-42282MEDIUMn8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP modeEPSS 0.3%CVE-2021-36340HIGHDell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulneEPSS 0.3%CVE-2021-21597HIGHDell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical acceEPSS 0.3%CVE-2021-21598LOWDell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with pEPSS 0.3%CVE-2021-21558HIGHDell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator EPSS 0.3%CVE-2021-3684—A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plainteEPSS 0.2%CVE-2025-13611LOWInsertion of Sensitive Information into Log File in GitLabEPSS 0.2%