Weaknesses of type CWE-203

350 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2026-64822MEDIUMdjangoSIGE 1.10 User Enumeration via ForgotPasswordViewEPSS 0.4%CVE-2024-21233MEDIUMVulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21EPSS 0.4%CVE-2019-25337MEDIUMOwnCloud 8.1.8 - Username DisclosureEPSS 0.4%CVE-2025-32789LOWEspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting FunctionEPSS 0.4%CVE-2026-56316MEDIUMCap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*EPSS 0.4%CVE-2022-24695MEDIUMBluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in NonEPSS 0.4%CVE-2021-47664MEDIUMEnumeration of valid user namesEPSS 0.4%CVE-2025-9109MEDIUMPortabilis i-Diario Password Recovery Endpoint email observable response discrepancyEPSS 0.4%CVE-2020-36888MEDIUMSpinetiX Fusion Digital Signage 3.4.8 Username Enumeration via Login ScriptEPSS 0.4%CVE-2026-19965MEDIUMautomad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancyEPSS 0.4%CVE-2024-5697MEDIUMA website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerabilEPSS 0.4%CVE-2026-65314MEDIUMElectric Postgres Sync Excluded-Column Value Inference via Subset Where ClausesEPSS 0.4%CVE-2020-10369MEDIUMCertain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory conteEPSS 0.4%CVE-2020-10367MEDIUMCertain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra"EPSS 0.4%CVE-2024-21251LOWVulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4EPSS 0.4%CVE-2024-30257LOW1Panel's password verification is suspected to have a timing attack vulnerabilityEPSS 0.4%CVE-2024-30176MEDIUMIn Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.EPSS 0.4%CVE-2023-30308MEDIUMAn issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions whicEPSS 0.4%CVE-2025-57770MEDIUMZITADEL user enumeration vulnerability in login UIEPSS 0.4%CVE-2025-6386HIGHTiming Attack Vulnerability in parisneo/lollmsEPSS 0.4%