Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2024-25959HIGHDell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low priEPSS 0.2%CVE-2026-55102MEDIUMhashi-vault-js: Vault token and secret values exposed in thrown errorsEPSS 0.2%CVE-2026-95815HIGHOpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL LoggingEPSS 0.2%CVE-2025-0976MEDIUMInformation Exposure Vulnerability in Hitachi Configuration Manager, Hitachi Ops Center API Configuration ManagerEPSS 0.2%CVE-2025-49846MEDIUMwire-ios accidentally logs message contentsEPSS 0.2%CVE-2025-3911MEDIUMExposure in Docker Desktop logs of environment variables configured for running containersEPSS 0.2%CVE-2026-84513MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 EPSS 0.2%CVE-2026-19483HIGHThe following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higherEPSS 0.2%CVE-2025-46752MEDIUMA insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to infEPSS 0.2%CVE-2025-46614LOWIn Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of SensEPSS 0.2%CVE-2026-40633HIGHDell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information iEPSS 0.2%CVE-2026-84527MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS SequoiaEPSS 0.2%CVE-2025-1053HIGHBrocade SANnav encryption key is logged in the debug logsEPSS 0.2%CVE-2024-25957MEDIUMDell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. EPSS 0.2%CVE-2026-9751MEDIUMSensitive data could be written to mongod.logEPSS 0.2%CVE-2026-71474HIGHInsights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx responseEPSS 0.2%CVE-2026-4788HIGHMultiple Vulnerabilities affect IBM Tivoli Netcool ImpactEPSS 0.2%CVE-2026-49810HIGHDell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability.EPSS 0.2%CVE-2024-45674LOWIBM Security Verify Bridge information disclosureEPSS 0.2%CVE-2025-0273MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to Insertion of Sensitive Information into Log File vulnerabilityEPSS 0.2%