Falhas do tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2025-26795HIGHApache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driverEPSS 0.7%CVE-2023-6802HIGHSensitive Information in Log File in GitHub Enterprise Server EPSS 0.7%CVE-2024-52009HIGHGit credentials are exposed in atlantis logsEPSS 0.7%CVE-2025-30677MEDIUMApache Pulsar IO Kafka Connector, Apache Pulsar IO Kafka Connect Adaptor: Sensitive information logged in Pulsar's Apache Kafka ConnectorsEPSS 0.7%CVE-2024-28236HIGHInsecure Variable Substitution in VelaEPSS 0.7%CVE-2024-41178HIGHApache Arrow Rust Object Store: AWS WebIdentityToken exposure in log filesEPSS 0.7%CVE-2023-22733LOWImproper Output Neutralization in Log Module in shopwareEPSS 0.7%CVE-2022-3018MEDIUMAn information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 1EPSS 0.7%CVE-2025-34183CRITICALIlevia EVE X1 Server 4.7.18.0.eden Credentials Leak Through Log DisclosureEPSS 0.7%CVE-2023-46675HIGHKibana Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2023-44155MEDIUMSensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35EPSS 0.7%CVE-2022-43954MEDIUMAn insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may EPSS 0.7%CVE-2023-34097HIGHDatabase password exposed in logs in hoppscotchEPSS 0.7%CVE-2024-32953HIGHWordPress Newsletters plugin <= 4.9.5 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2024-28154MEDIUMJenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by defauEPSS 0.7%CVE-2019-3891MEDIUMIt was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the CanEPSS 0.7%CVE-2023-25164HIGHSensitive Information leak via Script File in TinaCMSEPSS 0.7%CVE-2024-23448MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2023-49922MEDIUMBeats Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2023-22574HIGH Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI mEPSS 0.7%