Weaknesses of type CWE-200

4,917 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-20250—A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on theEPSS 0.7%CVE-2023-28336—Moodle: teacher can access names of users they do not have permission to accessEPSS 0.7%CVE-2023-42454CRITICALSQLpage vulnerable to public exposure of database credentialsEPSS 0.7%CVE-2023-1402—Moodle: course participation report shows roles the user should not seeEPSS 0.7%CVE-2022-32862MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.7.1, macOS Ventura 13, macOS Monterey 12.6.1EPSS 0.7%CVE-2023-50253CRITICALlaf logs leakEPSS 0.7%CVE-2022-42817MEDIUMA logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watEPSS 0.7%CVE-2024-0490MEDIUMHuaxia ERP getAllList information disclosureEPSS 0.7%CVE-2023-40691MEDIUMIBM Cloud Pak for Business Automation information disclosureEPSS 0.7%CVE-2024-3870MEDIUMContact Form 7 Database Addon – CFDB7 <= 1.2.6.8 - Unauthenticated Sensitive Information ExposureEPSS 0.7%CVE-2021-32477—The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capabilEPSS 0.7%CVE-2025-30224MEDIUMMyDumper arbitrary file read issueEPSS 0.7%CVE-2023-4796MEDIUMBooster for WooCommerce <= 7.1.0 - Authenticated (Subscriber+) Information Disclosure via ShortcodeEPSS 0.7%CVE-2023-45875—An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.EPSS 0.7%CVE-2023-40276CRITICALAn issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFileEPSS 0.7%CVE-2021-41090MEDIUMInstance config inline secret exposureEPSS 0.7%CVE-2023-47146MEDIUMIBM QRadar SIEM information disclosureEPSS 0.7%CVE-2022-42818MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. A user in a privileged network position mayEPSS 0.7%CVE-2021-22527MEDIUMInformation leakage vulnerability in NetIQ Access Manager versions prior to version 4.5.4 and 5.0.1EPSS 0.7%CVE-2023-33979MEDIUMgpt_academic's Configuration File vulnerable to File Information DisclosureEPSS 0.7%