Weaknesses of type CWE-203

350 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2026-79028MEDIUMObservable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crEPSS 0.3%CVE-2026-79030MEDIUMObservable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a cEPSS 0.3%CVE-2026-53933MEDIUMMaravel-Framework Vulnerable to Side-Channel Information Disclosure (Error Oracle) via Dynamic Route FuzzingEPSS 0.3%CVE-2026-78617MEDIUMWatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate LimitingEPSS 0.3%CVE-2025-11145HIGHUser Enumeration in CBK Soft's enVisionEPSS 0.3%CVE-2025-40732HIGHUser enumeration vulnerability in Daily Expense ManagerEPSS 0.3%CVE-2023-5872MEDIUMWago: Vulnerability in Smart Designer Web-ApplicationEPSS 0.3%CVE-2025-6056MEDIUMTiming difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackeEPSS 0.3%CVE-2026-33429MEDIUMParse Server: Protected field change detection oracle via LiveQuery watch parameterEPSS 0.3%CVE-2024-47057MEDIUMUser name enumeration possible due to response time difference on password reset formEPSS 0.3%CVE-2023-28200MEDIUMA validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, EPSS 0.3%CVE-2026-23937MEDIUMHost PSK extraction in Zabbix APIEPSS 0.3%CVE-2026-59341MEDIUMSealed Secrets: decryption oracle via Go template injection in unauthenticated controller endpointsEPSS 0.3%CVE-2025-47872MEDIUMEG4 Electronics EG4 Inverters Observable DiscrepancyEPSS 0.3%CVE-2025-56423MEDIUMAn issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitEPSS 0.3%CVE-2024-54002MEDIUMDependency-Track allows enumeration of managed users via /api/v1/user/login endpointEPSS 0.3%CVE-2025-59702HIGHEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.3%CVE-2025-10890CRITICALSide-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crEPSS 0.3%CVE-2025-43751MEDIUMUser enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 202EPSS 0.3%CVE-2026-56319MEDIUMCapgo - App Existence Oracle via GET /statistics/app/:app_idEPSS 0.3%