Weaknesses of type CWE-200

4,912 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2018-0269—A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote atEPSS 1.3%CVE-2021-21435MEDIUMInformation exposure in PDF exportEPSS 1.3%CVE-2022-39222CRITICALOAuth authorization code exposure in DexEPSS 1.3%CVE-2025-33051HIGHMicrosoft Exchange Server Information Disclosure VulnerabilityEPSS 1.3%CVE-2021-32817MEDIUMFile disclosure in express-hbsEPSS 1.3%CVE-2020-3537MEDIUMCisco Jabber for Windows Universal Naming Convention Link Handling VulnerabilityEPSS 1.3%CVE-2020-3360MEDIUMCisco IP Phones Series 7800 and Series 8800 Call Log Information Disclosure VulnerabilityEPSS 1.3%CVE-2022-0577HIGHExposure of Sensitive Information to an Unauthorized Actor in scrapy/scrapyEPSS 1.3%CVE-2023-29450HIGHUnauthorized limited filesystem access from preprocessingEPSS 1.3%CVE-2021-41125MEDIUMHTTP authentication credential leak to target websites in scrapyEPSS 1.3%CVE-2020-11013HIGHlookup Function Information Discolosure in HelmEPSS 1.3%CVE-2023-33960HIGHOpenProject vulnerable to project identifier information leakage through robots.txtEPSS 1.3%CVE-2022-36079HIGHParse Server vulnerable to brute force guessing of user sensitive data via search patternsEPSS 1.3%CVE-2023-34090HIGHDecidim vulnerable to sensitive data disclosureEPSS 1.3%CVE-2022-24768CRITICALImproper access control allows admin privilege escalation in Argo CDEPSS 1.3%CVE-2016-0715—Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote iEPSS 1.2%CVE-2023-45143LOWUndici's cookie header not cleared on cross-origin redirect in fetchEPSS 1.2%CVE-2021-41109HIGHLiveQuery publishes user session tokensEPSS 1.2%CVE-2023-42846—This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, tvOS 17.1, iOS EPSS 1.2%CVE-2022-4228MEDIUMSourceCodester Book Store Management System information disclosureEPSS 1.2%