Weaknesses of type CWE-200

4,921 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-47554HIGHExposure of Sensitive Information in Ormazabal productsEPSS 0.6%CVE-2019-3803MEDIUMConcourse includes token in CLI authentication callbackEPSS 0.6%CVE-2023-31927MEDIUMAn information disclosure in the web interface of Brocade Fabric OSEPSS 0.6%CVE-2022-0474LOWDisclosure of mail addressesEPSS 0.6%CVE-2023-1769MEDIUMSourceCodester Grade Point Average GPA Calculator index.php information disclosureEPSS 0.6%CVE-2022-22745MEDIUMSecuritypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects FirefoxEPSS 0.6%CVE-2022-41767MEDIUMAn issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP adEPSS 0.6%CVE-2023-2991—Fortra Globalscape Administration Server Information DisclosureEPSS 0.6%CVE-2023-1790MEDIUMSourceCodester Simple Task Allocation System index.php information disclosureEPSS 0.6%CVE-2023-41050MEDIUMInformation disclosure through Python's "format" functionality in Zope AccessControlEPSS 0.6%CVE-2022-31185MEDIUMEmail addresses are not hidden regardless of selected state in mprwebEPSS 0.6%CVE-2024-29400HIGHAn issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.EPSS 0.6%CVE-2023-28442HIGHGeoserver for GeoNode sensitive information leakEPSS 0.6%CVE-2024-28193MEDIUMDisclosure of Spotify API Access Tokens to Guest Users Using Public Tokens in your_spotifyEPSS 0.6%CVE-2026-3594MEDIUMRiaxe Product Customizer <= 2.4 - Unauthenticated Sensitive Information Disclosure via '/orders' REST API EndpointEPSS 0.6%CVE-2022-34313MEDIUMIBM CICS TX Standard is vulnerable to allowing attackers access to an application via insecure session cookiesEPSS 0.6%CVE-2024-52523MEDIUMNextcloud Server Custom defined credentials of external storages are sent back to the frontendEPSS 0.6%CVE-2023-0901MEDIUMExposure of Sensitive Information to an Unauthorized Actor in pixelfed/pixelfedEPSS 0.6%CVE-2020-36668MEDIUMJetBackup – WP Backup, Migrate & Restore <= 1.4.0 - Sensitive Information DisclosureEPSS 0.6%CVE-2024-9539MEDIUMAn information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to EPSS 0.6%