Weaknesses of type CWE-203

350 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2023-38327MEDIUMAn issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unautEPSS 0.3%CVE-2024-51477MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.3%CVE-2026-25562MEDIUMWeKan < 8.19 Attachments Publication Information DisclosureEPSS 0.3%CVE-2026-14071MEDIUMSide-channel information leakage in WebAudio in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data viaEPSS 0.3%CVE-2023-30312HIGHAn issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to EPSS 0.3%CVE-2024-47869LOWNon-constant-time comparison when comparing hashes in GradioEPSS 0.3%CVE-2026-8242MEDIUMIndustrial Application Software IAS Canias ERP Login RMI doAction response discrepancyEPSS 0.3%CVE-2026-4045MEDIUMprojectsend Auth.php response discrepancyEPSS 0.3%CVE-2024-45089MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.3%CVE-2026-44263MEDIUMWeblate: Private Translation Enumeration via Screenshot APIEPSS 0.3%CVE-2025-12888LOWConstant Time Issue with Xtensa-based ESP32 and X22519EPSS 0.3%CVE-2025-43743MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2025-43739MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2024-55374MEDIUMREDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.EPSS 0.3%CVE-2026-67193MEDIUMXlight FTP Server < 3.9.5 Information Disclosure via USER CommandEPSS 0.3%CVE-2026-23931MEDIUMFrontend plaintext macro value enumeration via the validatate.api.exists actionEPSS 0.3%CVE-2022-48220MEDIUMPotential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusioEPSS 0.3%CVE-2026-79242MEDIUMObservable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a craftEPSS 0.3%CVE-2026-79287MEDIUMObservable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafEPSS 0.3%CVE-2025-54477MEDIUMJoomla! Core - [20250902] User-Enumeration in passkey authentication methodEPSS 0.3%