Weaknesses of type CWE-200

4,909 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-21673MEDIUMOAuth Identity Token exposure in GrafanaEPSS 2.0%CVE-2021-41301CRITICALECOA BAS controller - Exposure of Sensitive Information to an Unauthorized ActorEPSS 2.0%CVE-2026-57219HIGHRabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurationsEPSS 2.0%CVE-2018-3831—Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured viEPSS 2.0%CVE-2025-22828MEDIUMApache CloudStack: Unauthorised access to annotationsEPSS 2.0%CVE-2019-1976HIGHCisco Industrial Network Director Configuration Data Information Disclosure VulnerabilityEPSS 2.0%CVE-2021-39200MEDIUMInformation Disclosure in wp_die() via JSONP in wordpressEPSS 2.0%CVE-2023-37379—Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" featureEPSS 2.0%CVE-2020-12802—remote graphics contained in docx format retrieved in 'stealth mode'EPSS 1.9%CVE-2019-11064—A vulnerability of remote credential disclosure was discovered in Advan VD-1EPSS 1.9%CVE-2022-26869CRITICALDell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentialEPSS 1.9%CVE-2021-41767—Private tunnel identifier may be included in the non-private details of active connectionsEPSS 1.9%CVE-2017-12169—It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remoteEPSS 1.9%CVE-2022-27949HIGHApache Airflow prior to 2.3.1 may include sensitive values in rendered templateEPSS 1.9%CVE-2019-0040MEDIUMJunos OS: Specially crafted packets sent to port 111 on any interface triggers responses from the management interfaceEPSS 1.9%CVE-2022-31090HIGHCURLOPT_HTTPAUTH option not cleared on change of origin in GuzzleEPSS 1.9%CVE-2022-31043HIGHFix failure to strip Authorization header on HTTP downgrade in GuzzleEPSS 1.9%CVE-2022-31042HIGHFailure to strip the Cookie header on change in host or HTTP downgrade in GuzzleEPSS 1.9%CVE-2019-5463—An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. ThiEPSS 1.9%CVE-2024-30569HIGHAn information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authenticaEPSS 1.9%