Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-62262MEDIUMInformation exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported vEPSS 0.1%CVE-2025-42935MEDIUMInformation Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Manager)EPSS 0.1%CVE-2026-73467MEDIUMOn affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) serversEPSS 0.1%CVE-2026-73466MEDIUMOn affected platforms running Arista EOS, under certain circumstances plaintext user passwordsEPSS 0.1%CVE-2026-73465MEDIUMOn affected platforms running Arista EOS, under certain circumstances plaintext private keysEPSS 0.1%CVE-2025-23289MEDIUMNVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive informatioEPSS 0.1%CVE-2026-21791LOWHCL Sametime for Android is affected by sensitive information disclosureEPSS 0.1%CVE-2026-2607MEDIUMMultiple vulnerabilities in IBM MQ Operator and Queue manager container imagesEPSS 0.1%CVE-2025-46313MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive EPSS 0.1%CVE-2025-10221MEDIUMHardcoded Password Exposure in AxxonNet (C-WerkNet) ARP Agent LogsEPSS 0.1%CVE-2026-20646LOWA logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read senEPSS 0.1%CVE-2025-30483MEDIUMDell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. EPSS 0.1%CVE-2025-48709MEDIUMBMC Control-M/Server cleartext database credentials in process lists and logsEPSS 0.1%CVE-2026-77285LOWOpenBao Agent Writes Secrets to StdoutEPSS 0.1%CVE-2025-36144LOWIBM watsonx.data information disclosureEPSS 0.1%CVE-2022-20458MEDIUMThe logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotifiEPSS 0.1%CVE-2026-20663LOWThe issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be aEPSS 0.1%CVE-2026-86597MEDIUMSensitive information written to logs by Snowflake driversEPSS 0.1%CVE-2024-51528MEDIUMVulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect servEPSS 0.1%CVE-2026-66068MEDIUMRabbitMQ: Shovel DEBUG log of full state exposes decrypted URIsEPSS 0.1%