Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-48671HIGH Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A remote attacker could potentially exploit tEPSS 0.8%CVE-2026-44486HIGHAxios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionEPSS 0.8%CVE-2023-28444CRITICALangular-server-side-configuration information disclosure vulnerability in monorepo with node.js backendEPSS 0.8%CVE-2024-33437HIGHAn issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS Style RulesEPSS 0.8%CVE-2024-34708MEDIUMDirectus allows redacted data extraction on the API through "alias"EPSS 0.8%CVE-2024-29384HIGHAn issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functEPSS 0.8%CVE-2024-29961HIGHsupply-chain attack riskEPSS 0.8%CVE-2018-19947MEDIUMThe vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disEPSS 0.8%CVE-2023-27591HIGHUnauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metricsEPSS 0.8%CVE-2022-35249MEDIUMA information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages EPSS 0.8%CVE-2023-39519HIGHCloudExplorer Lite sensitive information leakage vulnerabilityEPSS 0.8%CVE-2023-50263LOWNautobot allows unauthenticated db-file-storage viewsEPSS 0.8%CVE-2026-24098MEDIUMApache Airflow: Assigning single DAG permission leaked all DAGs Import ErrorsEPSS 0.8%CVE-2022-32740LOWInformation disclosure in the External InterfaceEPSS 0.8%CVE-2020-26220LOWInformation exposure in touchbase.aiEPSS 0.8%CVE-2023-4917MEDIUMLeyka <= 3.30.7 - Authenticated (Subscriber+) Sensitive Information ExposureEPSS 0.8%CVE-2022-36074MEDIUMAuthentication headers exposed on by Nextcloud ServerEPSS 0.8%CVE-2024-32870MEDIUMiTop hub connector Information disclosureEPSS 0.8%CVE-2024-33309HIGHAn issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information viEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%