Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-48258MEDIUMIn Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.EPSS 1.1%CVE-2026-26897CRITICALAn issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive informatioEPSS 1.1%CVE-2026-50429HIGHWindows Kernel Information Disclosure VulnerabilityEPSS 1.1%CVE-2023-38499LOWtypo3/cms-core Information Disclosure due to Out-of-scope Site ResolutionEPSS 1.1%CVE-2018-16467—A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.EPSS 1.1%CVE-2022-31130MEDIUMGrafana data source and plugin proxy endpoints leaking authentication tokens to some destination pluginsEPSS 1.1%CVE-2026-41615CRITICALMicrosoft Authenticator Information Disclosure VulnerabilityEPSS 1.1%CVE-2021-21421HIGHApiKey secret could be revelated on network issueEPSS 1.1%CVE-2022-24906LOWError in deleting deck cards attachment reveals the full application path in Nextcloud DeckEPSS 1.1%CVE-2022-31060MEDIUMBanner topic data is exposed on login-required Discourse sitesEPSS 1.1%CVE-2026-45539HIGHMicrosoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project treeEPSS 1.1%CVE-2024-43610HIGHCopilot Studio Information Disclosure VulnerabilityEPSS 1.1%CVE-2024-31869MEDIUMApache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config usedEPSS 1.1%CVE-2021-4024—A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spaEPSS 1.1%CVE-2023-1203—Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Manager PowerShell ModuEPSS 1.1%CVE-2021-39223MEDIUMFile path disclosure of shared files in Richdocuments applicationEPSS 1.1%CVE-2022-20680MEDIUMCisco Prime Service Catalog Information Disclosure VulnerabilityEPSS 1.1%CVE-2021-22770—A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensitive information to anEPSS 1.1%CVE-2023-49068—Apache DolphinScheduler: Information Leakage VulnerabilityEPSS 1.1%CVE-2018-16866MEDIUMAn out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attackerEPSS 1.1%