Weaknesses of type CWE-200

4,919 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-29197MEDIUMPimcore Preview Documents are not restricted to logged in users anymoreEPSS 0.7%CVE-2022-32805MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, maEPSS 0.7%CVE-2026-61899HIGHApache Tapestry: Possible classpath file download through URL manipulationEPSS 0.7%CVE-2025-21214MEDIUMWindows BitLocker Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-43410MEDIUMJenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling throEPSS 0.7%CVE-2023-33857MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.7%CVE-2025-1606MEDIUMSourceCodester Best Employee Management System backups.php information disclosureEPSS 0.7%CVE-2025-54376HIGHHoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.EPSS 0.7%CVE-2024-27769HIGHUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.7%CVE-2026-23486MEDIUMBlinko: Unauthorized User Information LeakEPSS 0.7%CVE-2024-31207MEDIUMVite's `server.fs.deny` did not deny requests for patterns with directoriesEPSS 0.7%CVE-2022-42883MEDIUMWordPress Quiz And Survey Master plugin <= 7.3.10 - Sensitive Information Disclosure vulnerabilityEPSS 0.7%CVE-2023-29287MEDIUMAdobe Commerce Information Exposure Security feature bypassEPSS 0.7%CVE-2023-28762CRITICALInformation Disclosure in SAP BusinessObjects Intelligence PlatformEPSS 0.7%CVE-2024-29897MEDIUMCreateWiki Leak of suppressed wiki requests outside of `CreateWikiGlobalWiki`EPSS 0.7%CVE-2024-28235HIGHContao possible cookie sharing with external domains while checking protected pages for broken linksEPSS 0.7%CVE-2024-52508HIGHNextcloud Mail auto configurator can be tricked into sending account information to wrong serversEPSS 0.7%CVE-2022-4054MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5EPSS 0.7%CVE-2022-39031MEDIUMSmart eVision - Exposure of Sensitive Information to an Unauthorized Actor -3EPSS 0.7%CVE-2020-5414MEDIUMApp Autoscaler logs credentialsEPSS 0.7%