Weaknesses of type CWE-200

4,909 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2019-10195MEDIUMA flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way thEPSS 1.8%CVE-2022-43684CRITICALACL bypass in Reporting functionalityEPSS 1.8%CVE-2021-20313—A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is poEPSS 1.8%CVE-2017-2609MEDIUMjenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autoEPSS 1.8%CVE-2018-1052—Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read aEPSS 1.8%CVE-2021-41082HIGHPrivate message title and participating users leaked in discourseEPSS 1.8%CVE-2025-26667MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.8%CVE-2024-21136HIGHVulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are aEPSS 1.8%CVE-2020-11021MEDIUMHTTP request which redirect to another hostname do not strip authorization header in Actions Http-ClientEPSS 1.8%CVE-2019-10223MEDIUMA security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 releasEPSS 1.8%CVE-2020-15099HIGHExposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMSEPSS 1.8%CVE-2019-10156MEDIUMA flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of EPSS 1.8%CVE-2016-7061LOWAn information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuEPSS 1.8%CVE-2016-6542—The MAC address/device tracking ID of an iTrack Easy can be obtained within range of the deviceEPSS 1.7%CVE-2026-32596HIGHGlances exposes the REST API without authenticationEPSS 1.7%CVE-2025-32395MEDIUMVite has an `server.fs.deny` bypass with an invalid `request-target`EPSS 1.7%CVE-2021-27434—Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework verEPSS 1.7%CVE-2018-0105—A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitiEPSS 1.7%CVE-2017-6614—A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authentiEPSS 1.7%CVE-2018-14803—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that couldEPSS 1.7%