Weaknesses of type CWE-200

4,912 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2017-15139MEDIUMA vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume EPSS 1.2%CVE-2021-23858HIGHInformation disclosureEPSS 1.2%CVE-2022-34704MEDIUMWindows Defender Credential Guard Information Disclosure VulnerabilityEPSS 1.2%CVE-2023-43791CRITICALLabel Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session TokensEPSS 1.2%CVE-2022-24865MEDIUMImproper access control in humhubEPSS 1.2%CVE-2017-12365—A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerabEPSS 1.2%CVE-2018-10627CRITICALEchelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versionsEPSS 1.2%CVE-2018-7496—An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header and referrer-policy reEPSS 1.2%CVE-2018-5477—An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 aEPSS 1.2%CVE-2017-9628—An Information Exposure issue was discovered in Saia Burgess Controls PCD Controllers with PCD firmware versions prior to 1.28.16 or 1.24.69EPSS 1.2%CVE-2023-45725—Apache CouchDB, IBM Cloudant: Privilege Escalation Using _design DocumentsEPSS 1.2%CVE-2024-51739HIGHUsers enumeration allowed through Rest API in Combodo iTopEPSS 1.2%CVE-2023-45348—Apache Airflow: Configuration information leakage vulnerabilityEPSS 1.2%CVE-2023-41752HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.2%CVE-2021-22917—Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowiEPSS 1.2%CVE-2020-2022HIGHPAN-OS: Panorama session disclosure during context switch into managed deviceEPSS 1.2%CVE-2022-32742MEDIUMA flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill thEPSS 1.2%CVE-2025-53728MEDIUMMicrosoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityEPSS 1.2%CVE-2024-30570MEDIUMAn information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication EPSS 1.2%CVE-2024-43416HIGHGLPI vulnerable to enumeration of users' email addresses by unauthenticated userEPSS 1.2%