Weaknesses of type CWE-200

4,909 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-36043MEDIUMOpen Management Infrastructure Information Disclosure VulnerabilityEPSS 1.4%CVE-2022-23952HIGHIn Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.EPSS 1.4%CVE-2021-32690MEDIUMRepository credentials passed to alternate domainEPSS 1.4%CVE-2022-0812—An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker EPSS 1.4%CVE-2021-31567MEDIUMWordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerabilityEPSS 1.4%CVE-2022-41876HIGHezplatform-graphql GraphQL queries can expose password hashesEPSS 1.4%CVE-2022-27241—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (AllEPSS 1.4%CVE-2019-15583—An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When anEPSS 1.4%CVE-2023-40511HIGHLG Simple Editor checkServer Authentication Bypass VulnerabilityEPSS 1.4%CVE-2023-40510HIGHLG Simple Editor getServerSetting Authentication Bypass VulnerabilityEPSS 1.4%CVE-2021-32747MEDIUMCustom variable protection and blacklists can be circumventedEPSS 1.4%CVE-2022-21712HIGHCookie and header exposure in twistedEPSS 1.4%CVE-2021-37629MEDIUMLack of ratelimit on Richdocuments OCS endpoint in nextcloudEPSS 1.4%CVE-2019-6852HIGHA CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium coEPSS 1.4%CVE-2022-24797MEDIUMExposure of Sensitive Information in PomeriumEPSS 1.4%CVE-2020-7510—A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtainEPSS 1.4%CVE-2024-42658HIGHAn issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's paraEPSS 1.4%CVE-2021-22905—Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being perforEPSS 1.4%CVE-2020-11009MEDIUMIDOR can reveal execution data and logs to unauthorized user in RundeckEPSS 1.4%CVE-2025-26263MEDIUMGeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure dEPSS 1.4%