Falhas do tipo CWE-532

857 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2021-3036MEDIUMPAN-OS: Administrator secrets are logged in web server logs when using the PAN-OS XML API incorrectlyEPSS 0.2%CVE-2024-30151HIGHHCL BigFix Service Management (SM) is susceptible to Broken Access Control VulnerabilityEPSS 0.2%CVE-2025-37727MEDIUMElasticsearch Insertion of sensitive information in log fileEPSS 0.2%CVE-2021-21561HIGHDell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIVEPSS 0.2%CVE-2024-51752LOWRefresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-nextjsEPSS 0.2%CVE-2020-7322MEDIUMExposure of Sensitive Information in ENS for WindowsEPSS 0.2%CVE-2021-41808LOWIn M-Files Server product with versions before 21.11.10775.0, enabling logging of federated authentication would write sensitive information to event logs.EPSS 0.2%CVE-2026-20708MEDIUMInsertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an infoEPSS 0.2%CVE-2021-26908LOWAutomox Agent Sensitive Log Information DisclosureEPSS 0.2%CVE-2026-44052HIGHLDAP simple-bind password exposure in log outputEPSS 0.2%CVE-2024-40791LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 EPSS 0.2%CVE-2025-36599MEDIUMDell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privEPSS 0.2%CVE-2025-55285LOW@backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`EPSS 0.2%CVE-2021-36289HIGHDell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may EPSS 0.2%CVE-2026-7824MEDIUMPaperCut Hive (Ricoh): Plain text password in logsEPSS 0.2%CVE-2025-70040MEDIUMAn issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allEPSS 0.2%CVE-2021-1442HIGHCisco IOS XE Software Plug-and-Play Privilege Escalation VulnerabilityEPSS 0.2%CVE-2021-44234—SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attackerEPSS 0.2%CVE-2023-31417MEDIUMElasticsearch Insertion of sensitive information in audit logsEPSS 0.2%CVE-2021-40364MEDIUMA vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 VEPSS 0.2%