Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2026-2401LOWCWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when EPSS 0.1%CVE-2025-48635HIGHIn multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. ThiEPSS 0.1%CVE-2026-21808MEDIUMHCL BigFix Quantum Risk Analyzer is affected by logging sensitive informationEPSS 0.1%CVE-2026-21786LOWHCL Sametime for iOS is affected by sensitive information disclosureEPSS 0.1%CVE-2022-33688LOWSensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers witEPSS 0.1%CVE-2022-33697LOWSensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with EPSS 0.1%CVE-2026-75573MEDIUMMongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are SuppliedEPSS 0.1%CVE-2025-32016MEDIUMMicrosoft Identity Web Exposes Client Secrets and Certificate Information in Service LogsEPSS 0.1%CVE-2026-17442MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.1%CVE-2026-0520LOWA potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticEPSS 0.1%CVE-2026-81530MEDIUMKMS master key exposure via unredacted credential serialization in driver settings stringEPSS 0.1%CVE-2025-63729CRITICALAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA CertifEPSS 0.1%CVE-2026-82716MEDIUMBotslab G980H Dashcams Insertion of Sensitive Information into Log FileEPSS —CVE-2026-82371HIGHPlaintext exposure of sensitive authentication data in SANnav discovery service log filesEPSS —CVE-2026-82372HIGHImproper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav before 3.0.1.aEPSS —CVE-2026-14442MEDIUMInformation exposure vulnerability in the job scheduling component of SANnav before 3.0.1aEPSS —CVE-2026-14443HIGHIncomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1aEPSS —CVE-2026-85417MEDIUMIncomplete property masking in the SANnav logging subsystemEPSS —