Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2022-27549MEDIUMHCL Launch could disclose sensitive database information to a local user in plain text.EPSS 0.1%CVE-2026-84525MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.EPSS 0.1%CVE-2026-58070MEDIUMA vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access toEPSS 0.1%CVE-2024-12569MEDIUMSensitive Information in Driver’s Log FileEPSS 0.1%CVE-2026-56459MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosureEPSS 0.1%CVE-2026-59911MEDIUMDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. EPSS 0.1%CVE-2026-18097MEDIUMIBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.EPSS 0.1%CVE-2025-24520MEDIUMInsertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2514.7.16.0 may allowEPSS 0.1%CVE-2025-53649MEDIUM"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. EPSS 0.1%CVE-2026-12086MEDIUMIBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File VulnerabilityEPSS 0.1%CVE-2026-59947MEDIUMComposer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)EPSS 0.1%CVE-2025-51497MEDIUMAn issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when thEPSS 0.1%CVE-2026-80124MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of SensEPSS 0.1%CVE-2025-54120CRITICALPCL Community Edition exposes login credentials in logsEPSS 0.1%CVE-2026-80056MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of SensEPSS 0.1%CVE-2026-5515MEDIUMIBM App Connect Enterprise is vulnerable to a confidential disclosureEPSS 0.1%CVE-2025-36573HIGHDell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user wEPSS 0.1%CVE-2026-32996HIGHThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.EPSS 0.1%CVE-2025-43888HIGHDell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerabEPSS 0.1%CVE-2025-43937MEDIUMDell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileEPSS 0.1%