Weaknesses of type CWE-200

4,909 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-38062MEDIUMIn JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurationsEPSS 1.4%CVE-2018-15718—Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command EPSS 1.4%CVE-2023-26268MEDIUMApache CouchDB, IBM Cloudant: Information sharing via couchjs processesEPSS 1.4%CVE-2026-45332HIGHAutomad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpointEPSS 1.4%CVE-2022-23948HIGHA flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously createdEPSS 1.4%CVE-2025-24204CRITICALThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.EPSS 1.4%CVE-2021-28566LOWMagento Commerce information disclosure during upload action leveraging a specially crafted fileEPSS 1.4%CVE-2023-44982MEDIUMWordPress WP Retina 2x Plugin <= 6.4.5 is vulnerable to Sensitive Data ExposureEPSS 1.4%CVE-2019-12664MEDIUMCisco IOS XE Software ISDN Data Leak VulnerabilityEPSS 1.4%CVE-2022-0654HIGHExposure of Sensitive Information to an Unauthorized Actor in fgribreau/node-request-retryEPSS 1.4%CVE-2016-10533—express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlEPSS 1.4%CVE-2023-46288—Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is setEPSS 1.4%CVE-2021-20019—A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead EPSS 1.4%CVE-2021-32770HIGHBasic-auth app bundle credential exposure in gatsby-source-wordpressEPSS 1.4%CVE-2023-1263MEDIUMCMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 - Information ExposureEPSS 1.4%CVE-2024-28247HIGHPihole Authenticated Arbitrary File Read with root privilegesEPSS 1.4%CVE-2025-0481MEDIUMD-Link DIR-878 HTTP POST Request dllog.cgi information disclosureEPSS 1.4%CVE-2021-24167—Web-Stat < 1.4.1 - API Key DisclosureEPSS 1.4%CVE-2017-20022HIGHSolare Solar-Log information disclosureEPSS 1.4%CVE-2018-12594HIGHReliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct request for the data/fileiEPSS 1.4%