Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2017-20019MEDIUMSolare Solar-Log Config information disclosureEPSS 1.0%CVE-2017-20110MEDIUMTeleopti WFM Administration Credentials information disclosureEPSS 1.0%CVE-2023-35934MEDIUMyt-dlp File Downloader cookie leakEPSS 1.0%CVE-2023-40023MEDIUMYaklang Plugin's Fuzztag Component Allows Unauthorized Local File ReadingEPSS 1.0%CVE-2023-39999MEDIUMWordPress < 6.3.2 is vulnerable to Broken Access ControlEPSS 1.0%CVE-2022-3348MEDIUMExposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljetEPSS 1.0%CVE-2024-28849MEDIUMProxy-Authorization header kept across hosts in follow-redirectsEPSS 1.0%CVE-2024-26470HIGHA host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackeEPSS 1.0%CVE-2022-29232MEDIUMExposure of messages in BigBlueButton public chatsEPSS 1.0%CVE-2020-11033MEDIUMAble to read any token through API user endpoint in GLPIEPSS 1.0%CVE-2022-25594MEDIUMMicroprogram parking lot management system - Exposure of Sensitive Information to an Unauthorized ActorEPSS 1.0%CVE-2023-0994HIGHExposure of Sensitive Information to an Unauthorized Actor in francoisjacquet/rosariosisEPSS 1.0%CVE-2025-59284LOWWindows NTLM Spoofing VulnerabilityEPSS 1.0%CVE-2019-15592—GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associatEPSS 1.0%CVE-2022-24784LOWDiscoverability of user password hash in Statamic CMSEPSS 1.0%CVE-2022-22183HIGHJunos OS Evolved: A remote attacker may cause a CPU Denial of Service by sending genuine traffic to a device on a specific IPv4 port.EPSS 1.0%CVE-2021-32473—It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to EPSS 1.0%CVE-2021-4377MEDIUMDoneren met Mollie <= 2.8.4 - Information DisclosureEPSS 1.0%CVE-2019-15579—An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where thEPSS 1.0%CVE-2018-25081HIGHBitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have beEPSS 1.0%