Weaknesses of type CWE-200

4,912 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-24867HIGHLDAP password exposure in glpiEPSS 1.3%CVE-2021-20281—It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.EPSS 1.3%CVE-2020-3391MEDIUMCisco Digital Network Architecture Center Information Disclosure VulnerabilityEPSS 1.3%CVE-2022-39253MEDIUMGit subject to exposure of sensitive information via local clone of symbolic linksEPSS 1.3%CVE-2022-31112HIGHProtected fields exposed via LiveQuery in parse-serverEPSS 1.3%CVE-2016-10530—The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secEPSS 1.3%CVE-2019-3992—ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the serverEPSS 1.3%CVE-2023-26049LOWCookie parsing of quoted values can exfiltrate values from other cookies in Eclipse JettyEPSS 1.3%CVE-2022-0813MEDIUMPhpMyAdmin exposure of sensitive informationEPSS 1.3%CVE-2020-1628MEDIUMJunos OS: EX4300: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfacesEPSS 1.3%CVE-2022-0430LOWExposure of Sensitive Information to an Unauthorized Actor in httpie/httpieEPSS 1.3%CVE-2017-6709—A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access adminisEPSS 1.3%CVE-2022-23067HIGHToolJet - Token Leakage via Referer HeaderEPSS 1.3%CVE-2018-13294MEDIUMInformation exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated usEPSS 1.3%CVE-2018-13295MEDIUMInformation exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authentEPSS 1.3%CVE-2026-53598HIGHPrompty: Arbitrary File Read via ${file:path} Reference ExpansionEPSS 1.3%CVE-2016-6539—TrackR Bravo MAC address can be exposed in close proximity and used to obtain the device IDEPSS 1.3%CVE-2026-6826MEDIUMConcrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controllerEPSS 1.3%CVE-2018-15456MEDIUMCisco Identity Services Engine Password Recovery VulnerabilityEPSS 1.3%CVE-2020-4045HIGHInformation disclosure in SSB-DBEPSS 1.3%