Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2021-36318MEDIUMDell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentiaEPSS 0.2%CVE-2022-27636MEDIUMOn F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prEPSS 0.2%CVE-2025-43354MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 2EPSS 0.2%CVE-2023-23505LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.6.3, macOS VentEPSS 0.2%CVE-2026-8482MEDIUMInformation leak in NSRPC client historyEPSS 0.2%CVE-2026-25211LOWLlama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.EPSS 0.2%CVE-2023-25682MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.2%CVE-2026-46358MEDIUMOpenBao's Inline Auth Incorrectly Redacted HeadersEPSS 0.2%CVE-2024-6977MEDIUMCato Networks Windows SDP Client Sensitive data in trace logs can lead to account takeoverEPSS 0.2%CVE-2025-11446HIGHInsertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain CredentialsEPSS 0.2%CVE-2022-0010HIGHQCS 800xA Vulnerability identified in system log filesEPSS 0.2%CVE-2025-43303MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 2EPSS 0.2%CVE-2025-38745MEDIUMDell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in EPSS 0.2%CVE-2026-14163HIGHIn affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment vaEPSS 0.2%CVE-2026-43992CRITICALJunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameterEPSS 0.2%CVE-2026-6720HIGHCalicoctl leaks cluster credentials to stderr when verbose logging is enabledEPSS 0.2%CVE-2023-31207MEDIUMAutomation user secret logged to Apache access logEPSS 0.2%CVE-2025-20373LOWSensitive Information Disclosure in “_internal“ index through Splunk Add-On for Palo Alto NetworksEPSS 0.2%CVE-2022-0021LOWGlobalProtect App: Information Exposure Vulnerability When Using Connect Before LogonEPSS 0.2%CVE-2025-66910MEDIUMTurms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. ThEPSS 0.2%