Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-13321LOWMattermost Desktop App logging sensitive information and fails to clear data on server deletionEPSS 0.1%CVE-2025-27496LOWSnowflake JDBC Driver client-side encryption key in DEBUG logsEPSS 0.1%CVE-2025-46329LOWSnowflake Connector for C/C++ inserts client-side encryption key in DEBUG logsEPSS 0.1%CVE-2021-21508MEDIUMDell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit thisEPSS 0.1%CVE-2026-1495MEDIUMInsertion of Sensitive Information into Log File vulnerability in AVEVA PI to CONNECT AgentEPSS 0.1%CVE-2023-50301LOWIBM Transformation Extender Advanced information disclosureEPSS 0.1%CVE-2022-45098MEDIUM Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticateEPSS 0.1%CVE-2025-68919MEDIUMFujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenancEPSS 0.1%CVE-2026-46467MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.1%CVE-2026-19502MEDIUMInsufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLIEPSS 0.1%CVE-2025-36133MEDIUMIBM App Connect Enterprise information disclosureEPSS 0.1%CVE-2024-29955MEDIUMInsertion of Sensitive Information into Brocade SANnav Log FileEPSS 0.1%CVE-2026-0936MEDIUMInsertion of Sensitive Information into LogfileEPSS 0.1%CVE-2026-16689MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.1%CVE-2026-19649MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.1%CVE-2024-11604HIGHInsertion of Sensitive Information into Log FileEPSS 0.1%CVE-2025-12996MEDIUMMedtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errorEPSS 0.1%CVE-2025-13755MEDIUMIBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase bucketsEPSS 0.1%CVE-2025-3456LOWOn affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-cEPSS 0.1%CVE-2026-0267MEDIUMGlobalProtect App: Information Exposure Vulnerability on macOSEPSS 0.1%