Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-6624LOWVersions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debugEPSS 0.2%CVE-2026-20165MEDIUMSensitive Information Disclosure in MongoClient logging channel in Splunk EnterpriseEPSS 0.2%CVE-2025-49009MEDIUMPara Inserts Sensitive Information into Log File for Facebook authenticationEPSS 0.2%CVE-2025-48955MEDIUMPara Server Logs Sensitive InformationEPSS 0.2%CVE-2023-6833MEDIUMInformation Exposure Vulnerability in Hitachi Ops Center AdministratorEPSS 0.2%CVE-2023-27502LOWInsertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2316.5.1.2 may allow EPSS 0.2%CVE-2026-44969LOWdbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is EnabledEPSS 0.2%CVE-2024-0912HIGHCCURE passwords exposed to administratorsEPSS 0.2%CVE-2024-40096LOWThe com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.EPSS 0.2%CVE-2023-30430MEDIUMIBM Security Verify Access information disclosureEPSS 0.2%CVE-2024-40679MEDIUMIBM Db2 information disclosureEPSS 0.2%CVE-2026-28868MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, mEPSS 0.2%CVE-2023-25604MEDIUMAn insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext pEPSS 0.2%CVE-2026-0637MEDIUMSensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 ProductsEPSS 0.2%CVE-2025-2002MEDIUMCWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials whEPSS 0.2%CVE-2026-44479MEDIUMVercel: Non-interactive mode includes CLI arguments in suggested command outputEPSS 0.2%CVE-2023-3335MEDIUMInformation Exposure Vulnerability in Hitachi Ops Center AdministratorEPSS 0.2%CVE-2026-41004MEDIUMWhen enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.EPSS 0.2%CVE-2025-23413MEDIUMBIG-IP Next Central Manager vulnerabilityEPSS 0.2%CVE-2026-11819MEDIUMCommunity.general: community.general keyring_info — os keyring passphrase returned in plaintextEPSS 0.2%