Falhas do tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2023-31422CRITICALKibana Insertion of Sensitive Information into Log FileEPSS 0.8%CVE-2022-43936MEDIUMBrocade Fabric OS switch passwords when debugging is enabledEPSS 0.8%CVE-2021-37709MEDIUMInsecure direct object reference of log files of the Import/Export featureEPSS 0.8%CVE-2021-23046On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from AcceEPSS 0.8%CVE-2025-24169HIGHA logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be aEPSS 0.8%CVE-2024-0831MEDIUMVault May Expose Sensitive Information When Configuring An Audit Log DeviceEPSS 0.8%CVE-2022-28859MEDIUMOn F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-iEPSS 0.8%CVE-2022-0338MEDIUMInsertion of Sensitive Information into Log File in delgan/loguruEPSS 0.8%CVE-2024-27784HIGHMultiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may alloEPSS 0.8%CVE-2019-14885MEDIUMA flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security aEPSS 0.7%CVE-2026-31987HIGHApache Airflow: JWT token appearing in logsEPSS 0.7%CVE-2020-3447MEDIUMCisco Email Security Appliance and Cisco Content Security Management Appliance Information Disclosure VulnerabilityEPSS 0.7%CVE-2024-52067MEDIUMApache NiFi: Potential Insertion of Sensitive Parameter Values in Debug LogEPSS 0.7%CVE-2020-2044LOWPAN-OS: Passwords may be logged in clear text while storing operational command (op command) historyEPSS 0.7%CVE-2020-2043LOWPAN-OS: Passwords may be logged in clear text when using after-change-detail custom syslog field for config logsEPSS 0.7%CVE-2026-20818MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-3902MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5EPSS 0.7%CVE-2023-3993MEDIUMInsertion of Sensitive Information into Log File in GitLabEPSS 0.7%CVE-2025-26864HIGHApache IoTDB: Exposure of Sensitive Information in IoTDB OpenID AuthenticationEPSS 0.7%CVE-2025-26795HIGHApache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driverEPSS 0.7%