Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-32712MEDIUMInformation leakage in Error HandlerEPSS 1.1%CVE-2024-37325HIGHAzure Science Virtual Machine (DSVM) Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2019-5465—An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosEPSS 1.1%CVE-2021-41239MEDIUMUser enumeration setting not respected in Nextcloud serverEPSS 1.1%CVE-2020-3472MEDIUMCisco Webex Meetings User Email Address Information Disclosure VulnerabilityEPSS 1.1%CVE-2023-33165MEDIUMMicrosoft SharePoint Server Security Feature Bypass VulnerabilityEPSS 1.1%CVE-2022-23498HIGHWhen query caching is enabled in Grafana users can query another users sessionEPSS 1.1%CVE-2022-2117MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information DisclosureEPSS 1.1%CVE-2024-26144MEDIUMPossible Sensitive Session Information Leak in Active StorageEPSS 1.1%CVE-2022-23619MEDIUMInformation exposure in xwiki-platformEPSS 1.1%CVE-2017-20194MEDIUMFormidable Form Builder < 2.05.03 - Unauthenticated Information DisclosureEPSS 1.1%CVE-2022-24837MEDIUMEnumerable upload file names in hedgedocEPSS 1.1%CVE-2022-30598—A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise haEPSS 1.1%CVE-2021-41124HIGHSplash authentication credentials potentially leaked to target websites in scrapy-splashEPSS 1.1%CVE-2021-25369MEDIUMAn improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.EPSS 1.1%KEVCVE-2024-33575MEDIUMWordPress User Meta plugin <= 3.0 - Sensitive Data Exposure vulnerabilityEPSS 1.1%CVE-2024-26177MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.1%CVE-2020-11059CRITICALExposure of Sensitive Information to an Unauthorized Actor in AEgirEPSS 1.1%CVE-2017-20007MEDIUMInformation Exposure in INGEPAC DA AUEPSS 1.1%CVE-2023-34134—Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to reaEPSS 1.1%