Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-7445MEDIUMKubernetes secrets-store-sync-controller discloses service account tokens in logsEPSS 0.2%CVE-2025-0495MEDIUMSecrets leakage to telemetry endpoint via cache backend configuration via buildxEPSS 0.2%CVE-2024-25030MEDIUMIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be rEPSS 0.2%CVE-2024-22337MEDIUMIBM QRadar Suite information disclosureEPSS 0.2%CVE-2024-22335MEDIUMIBM QRadar Suite information disclosureEPSS 0.2%CVE-2023-22869MEDIUMIBM Aspera Faspex information disclosureEPSS 0.2%CVE-2026-1265MEDIUMIBM InfoSphere Information Server is vulnerable due to sensitive information written to a log fileEPSS 0.2%CVE-2022-43923MEDIUMIBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: EPSS 0.2%CVE-2022-48228MEDIUMAn issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify and Sentinel InstallerEPSS 0.2%CVE-2025-46277MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, watchOS 26.2.EPSS 0.2%CVE-2026-25918MEDIUMunity-cli Exposes Plaintext Credentials in Debug Logs (sign-package command)EPSS 0.2%CVE-2023-36494MEDIUMF5OS-A vulnerabilityEPSS 0.2%CVE-2023-3363LOWInsertion of Sensitive Information into Log File in GitLabEPSS 0.2%CVE-2021-44862HIGHSensitive Information store in NSClient logsEPSS 0.2%CVE-2024-44205MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOSEPSS 0.2%CVE-2024-6060CRITICALAn information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP reqEPSS 0.2%CVE-2022-46647LOWInsertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable informEPSS 0.2%CVE-2026-40091MEDIUMSpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logsEPSS 0.2%CVE-2026-8330MEDIUMInsertion of Sensitive Information into Log File in GitLabEPSS 0.2%CVE-2025-52580LOWInsertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploited, sensitive user EPSS 0.2%