Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2021-21601HIGHDell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CISEPSS 0.2%CVE-2021-21546HIGHDell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vulnerability. A local lEPSS 0.2%CVE-2021-32801MEDIUMExceptions may have logged Encryption-at-Rest key content in Nextcloud serverEPSS 0.2%CVE-2025-6711MEDIUMIncomplete Redaction of Sensitive Information in MongoDB Server LogsEPSS 0.2%CVE-2026-50205HIGHPlaintext Log Credential LeakageEPSS 0.2%CVE-2026-86049HIGHJupyter Server: 5xx request logging leaks token-bearing Referer header valuesEPSS 0.2%CVE-2023-22447LOWInsertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a prEPSS 0.2%CVE-2025-24145LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS SEPSS 0.2%CVE-2025-46777LOWA insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 EPSS 0.2%CVE-2024-24272HIGHAn issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked EPSS 0.2%CVE-2025-6391HIGHJSON Web Token (JWT) Exposure in Log FilesEPSS 0.2%CVE-2022-2084MEDIUMsensitive data exposure in cloud-init logsEPSS 0.2%CVE-2026-32598MEDIUMOneUptime: Password Reset Token Logged at INFO LevelEPSS 0.2%CVE-2022-27888MEDIUMThe Foundry Issues service was found to be logging in a manner that captured session tokens.EPSS 0.2%CVE-2022-31239MEDIUMDell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerabilityEPSS 0.2%CVE-2026-12947HIGHIBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodesEPSS 0.2%CVE-2020-10052—A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data,EPSS 0.2%CVE-2025-66411HIGHCoder logged sensitive objects unsanitizedEPSS 0.2%CVE-2024-5557MEDIUMCWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attackeEPSS 0.2%CVE-2021-36318MEDIUMDell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentiaEPSS 0.2%