Weaknesses of type CWE-201

411 results

Exposição de informações sensíveis em dados transmitidos

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais, chaves) em comunicações que não deveriam conter essas informações. O desenvolvedor inclui acidentalmente ou por falha de lógica dados confidenciais em respostas, logs, cookies ou requisições que podem ser interceptadas ou expostas.

Example

Um sistema de e-commerce retorna a senha do usuário em uma resposta JSON após login, ou inclui o token de autenticação em um parâmetro GET visível na URL, permitindo que seja capturada em logs de servidor ou histórico do navegador.

How to mitigate

Revise todo dado enviado em respostas HTTP, cookies e headers para eliminar informações sensíveis; use variáveis de ambiente para credenciais, nunca as codifique; aplique sanitização antes de escrever em logs; utilize HTTPS obrigatoriamente e tokens seguros com ciclo de vida limitado.

CVE-2022-28224MEDIUMCalico and Calico Enterprise may be vulnerable to route hijacking with the floating IP featureEPSS 0.6%CVE-2023-4002MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%CVE-2023-1975HIGHInsertion of Sensitive Information Into Sent Data in answerdev/answerEPSS 0.6%CVE-2024-53804HIGHWordPress WP Mailster plugin <= 1.8.16.0 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-34812MEDIUMWordPress ShopBuilder plugin <= 2.1.8 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-34556MEDIUMWordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.5.4 - Sensitive Data Exposure via Exported File vulnerabilityEPSS 0.6%CVE-2026-39912CRITICALv2board / Xboard Authentication Token Exposure via loginWithMailLinkEPSS 0.6%CVE-2023-3102MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%CVE-2024-35189MEDIUMSensitive Data Disclosure Vulnerability in Connection Configuration Endpoints in FidesEPSS 0.6%CVE-2022-23488MEDIUMBigBlueButton vulnerable to Insertion of Sensitive Information Into Sent DataEPSS 0.6%CVE-2023-6916HIGHInformation disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1EPSS 0.6%CVE-2025-59509MEDIUMWindows Speech Recognition Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-2620MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2024-25148MEDIUMIn Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, anEPSS 0.5%CVE-2024-56300HIGHWordPress Post/Page Copying Tool plugin <= 2.0.0 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-46665LOWAn insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in EPSS 0.5%CVE-2026-82209HIGHdomain-scoped PSL domain cookieEPSS 0.5%CVE-2023-1825LOWInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2021-1425MEDIUMCisco Cisco Email Security Appliance and Content Security Management Appliance Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-28173MEDIUMIn JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosedEPSS 0.5%