Falhas do tipo CWE-532

850 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2024-2302MEDIUMEasy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information ExposureEPSS 0.6%CVE-2024-23686MEDIUMDependencyCheck Debug Mode Logging of NVD API KeyEPSS 0.6%CVE-2025-31213HIGHA logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, mEPSS 0.6%CVE-2023-33001HIGHJenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the buildEPSS 0.6%CVE-2025-24457MEDIUMIn JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logsEPSS 0.6%CVE-2023-0436MEDIUMSecret logging may occur in debug mode of Atlas Operator EPSS 0.6%CVE-2018-3828Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exceptiEPSS 0.6%CVE-2020-11932LOWSubiquity server installer logged LUKS full disk encryption passwordEPSS 0.6%CVE-2025-59258MEDIUMWindows Active Directory Federation Services (ADFS) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-49923MEDIUMEnterprise Search Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2026-21222MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-6687MEDIUMElastic Agent Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2024-31259HIGHWordPress SearchIQ plugin <= 4.5 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.6%CVE-2021-39011MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2024-34550MEDIUMWordPress Dynamics 365 Integration plugin <= 1.3.17 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2022-2721HIGHIn affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plainEPSS 0.6%CVE-2024-35196LOWSlack integration leaks sensitive information in logs in SentryEPSS 0.6%CVE-2025-31479HIGHcanonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception outputEPSS 0.6%CVE-2020-14330MEDIUMAn Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content aEPSS 0.6%CVE-2022-23716MEDIUMA flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in dEPSS 0.6%