Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-24389MEDIUMSMTP Password will be shown in cleartext on some SMTP errorsEPSS 0.1%CVE-2026-78627HIGHImproper Credential Protection in Okta Hyperdrive Integration Installer LoggingEPSS 0.1%CVE-2025-26332HIGHTechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. EPSS 0.1%CVE-2024-11165MEDIUMAn information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration reEPSS 0.1%CVE-2025-54781LOWHimmelblau leaks an Intune service access token in its logsEPSS 0.1%CVE-2025-30105HIGHDell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker wEPSS 0.1%CVE-2024-12057LOWUser credentials recorded in log filesEPSS 0.1%CVE-2025-5781MEDIUMInformation Exposure Vulnerability in Hitachi Configuration Manager, Hitachi Ops Center API Configuration ManagerEPSS 0.1%CVE-2026-0519MEDIUMInformation Disclosure in Secure Access Between 12.70 and 14.20EPSS 0.1%CVE-2026-78631MEDIUMImproper Restriction of Sensitive Information in Okta Hyperdrive Agent LoggingEPSS 0.1%CVE-2026-59326LOWHTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language ServerEPSS 0.1%CVE-2025-6392MEDIUMDaily Data Dump Collector logs database password in cleartext when running docker exec commands (CVE-2025-6392)EPSS 0.1%CVE-2026-80169LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of SensEPSS 0.1%CVE-2026-79966LOWCWE-532: Insertion of Sensitive Information into Log FileEPSS 0.1%CVE-2026-25193HIGHInsertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentiaEPSS 0.1%CVE-2025-4234LOWCortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of CredentialsEPSS 0.1%CVE-2025-14010MEDIUMAnsible-collection-community-general: ansible-collection-community-general: keycloak user module leaks credentials in verbose outputEPSS 0.1%CVE-2025-6587MEDIUMExposure of system environment variables in Docker Desktop diagnostic logsEPSS 0.1%CVE-2021-22518MEDIUMSensitive Information logging in NetIQ Identity Manager DriverEPSS 0.1%CVE-2026-44105MEDIUMCleartext password in logsEPSS 0.1%