Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-52580LOWInsertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploited, sensitive user EPSS 0.2%CVE-2022-27599MEDIUMQVR Pro ClientEPSS 0.2%CVE-2023-22572HIGH Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A lEPSS 0.2%CVE-2025-43485MEDIUMPoly Clariti Manager - Multiple Security VulnerabilitiesEPSS 0.2%CVE-2025-43517LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.3, macOS SonomEPSS 0.2%CVE-2023-40682MEDIUMIBM App Connect Enterprise information disclosureEPSS 0.2%CVE-2024-8264MEDIUMSensitive information in agent log file when detailed logging is enabled with Robot Schedule Enterprise prior to version 3.05EPSS 0.2%CVE-2022-39876MEDIUMInsertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI.EPSS 0.2%CVE-2026-20668MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, mEPSS 0.2%CVE-2022-41553MEDIUMInformation Exposure Vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center AnalyzerEPSS 0.2%CVE-2025-53885MEDIUMDirectus doesn't redact sensitive user data when logging via event hooksEPSS 0.2%CVE-2022-35719MEDIUMIBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local userEPSS 0.2%CVE-2023-39447MEDIUMBIG-IP APM Guided Configuration vulnerabilityEPSS 0.2%CVE-2026-22798MEDIUMhermes's raw options logging may disclose secrets passed in via subcommand options argumentEPSS 0.2%CVE-2024-27849LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be aEPSS 0.2%CVE-2025-1998MEDIUMIBM UrbanCode Deploy (UCD) / IBM DevOps Deploy information disclosureEPSS 0.2%CVE-2025-48374MEDIUMzot logs secretsEPSS 0.2%CVE-2019-25683MEDIUMFileZilla 3.40.0 Denial of Service via Local SearchEPSS 0.2%CVE-2026-28923HIGHA logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26EPSS 0.2%CVE-2022-48435LOWIn JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log fileEPSS 0.2%