Falhas do tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2020-5225MEDIUMLog injection in SimpleSAMLphpEPSS 0.7%CVE-2023-26023MEDIUMIBM Planning Analytics Cartridge for Cloud Pak for Data information disclosureEPSS 0.7%CVE-2023-31426MEDIUMscp, sftp, ftp servers passwords in supportsaveEPSS 0.7%CVE-2023-46671HIGHKibana Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2022-34369HIGHDell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive inforEPSS 0.7%CVE-2023-41934Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of EPSS 0.7%CVE-2023-25721MEDIUMVeracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and whEPSS 0.6%CVE-2022-31684MEDIUMReactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers mEPSS 0.6%CVE-2024-28072MEDIUMArbitrary File Overwrite VulnerabilityEPSS 0.6%CVE-2023-20891MEDIUMVMware Tanzu Application Service for VMs and Isolation Segment information disclosure vulnerabilityEPSS 0.6%CVE-2023-4380MEDIUMPlatform: token exposed at importing projectEPSS 0.6%CVE-2023-0815MEDIUMPlaintext Password Present in the Web logsEPSS 0.6%CVE-2022-43870MEDIUMIBM Spectrum Virtualize information disclosureEPSS 0.6%CVE-2025-67223HIGHThe Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable nameEPSS 0.6%CVE-2023-48708MEDIUMInsertion of Sensitive Information into Log in codeigniter4/shieldEPSS 0.6%CVE-2026-12053HIGHInsertion of Sensitive Information into Log File in GitLabEPSS 0.6%CVE-2023-22575HIGHDell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privilegesEPSS 0.6%CVE-2023-31056CRITICALCloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employEPSS 0.6%CVE-2025-47979MEDIUMMicrosoft Failover Cluster Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-2302MEDIUMEasy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information ExposureEPSS 0.6%