Falhas do tipo CWE-532

847 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2021-22030In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) infoEPSS 1.0%CVE-2020-10712HIGHA flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry oEPSS 1.0%CVE-2018-1072MEDIUMovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of tEPSS 1.0%CVE-2022-24875MEDIUMPotential Secrets being logged to disk in CVEProject/cve-servicesEPSS 1.0%CVE-2025-46432MEDIUMIn JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logsEPSS 1.0%CVE-2022-20807MEDIUMCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 1.0%CVE-2021-34800Sensitive information could be loggedEPSS 1.0%CVE-2024-29945HIGHSplunk Authentication Token Exposure in Debug Log in Splunk EnterpriseEPSS 0.9%CVE-2022-20806MEDIUMCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 0.9%CVE-2020-5389CRITICALDell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information discEPSS 0.9%CVE-2022-20768MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure VulnerabilityEPSS 0.9%CVE-2022-20809MEDIUMCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 0.9%CVE-2025-21321MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-21319MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-21320MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-21318MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-21316MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-54236MEDIUMvLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic routerEPSS 0.9%CVE-2021-36544HIGHIncorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.EPSS 0.9%CVE-2021-27022A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being loggEPSS 0.9%