Weaknesses of type CWE-201

411 results

Exposição de informações sensíveis em dados transmitidos

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais, chaves) em comunicações que não deveriam conter essas informações. O desenvolvedor inclui acidentalmente ou por falha de lógica dados confidenciais em respostas, logs, cookies ou requisições que podem ser interceptadas ou expostas.

Example

Um sistema de e-commerce retorna a senha do usuário em uma resposta JSON após login, ou inclui o token de autenticação em um parâmetro GET visível na URL, permitindo que seja capturada em logs de servidor ou histórico do navegador.

How to mitigate

Revise todo dado enviado em respostas HTTP, cookies e headers para eliminar informações sensíveis; use variáveis de ambiente para credenciais, nunca as codifique; aplique sanitização antes de escrever em logs; utilize HTTPS obrigatoriamente e tokens seguros com ciclo de vida limitado.

CVE-2024-32796MEDIUMWordPress WP Fusion Lite plugin <= 3.42.10 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2019-14849MEDIUMA vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could useEPSS 0.5%CVE-2025-67721MEDIUMAircompressor's Snappy and LZ4 Java-based decompressor implementation can leak information from reused output bufferEPSS 0.5%CVE-2023-1401MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2026-4035HIGHEnvironment Variable Resolution Vulnerability in mlflow/mlflowEPSS 0.5%CVE-2026-64643MEDIUMNext.js: Unauthenticated Disclosure of Internal Server Function endpointsEPSS 0.5%CVE-2024-1435MEDIUMWordPress Tainacan plugin <= 0.20.6 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2023-4378MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2026-42880CRITICALArgoCD ServerSideDiff is vulnerable to Kubernetes Secret ExtractionEPSS 0.5%CVE-2024-23506HIGHWordPress InstaWP Connect plugin <= 0.1.0.9 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-53196MEDIUMWordPress JetEngine <= 3.7.0 - Sensitive Data Exposure VulnerabilityEPSS 0.5%CVE-2024-31278MEDIUMWordPress Premium Addons for Elementor plugin <= 4.10.22 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-7205CRITICALsharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary userEPSS 0.5%CVE-2025-9958HIGHInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-49408CRITICALWordPress Templately Plugin <= 3.2.7 - Sensitive Data Exposure VulnerabilityEPSS 0.5%CVE-2025-31842MEDIUMWordPress Viral Loops WP Integration Plugin <= 3.4.0 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-5483HIGHOdh-dashboard: odh dashboard kubernetes service account exposureEPSS 0.5%CVE-2023-49261HIGHSensitive authentication-related value accessible publiclyEPSS 0.5%CVE-2024-13259HIGHImage Sizes - Moderately critical - Access bypass - SA-CONTRIB-2024-023EPSS 0.5%CVE-2024-13254HIGHREST Views - Moderately critical - Information Disclosure - SA-CONTRIB-2024-018EPSS 0.5%