Weaknesses of type CWE-203

350 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2022-46724LOWThis issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.4 and iPadOS 16.4. A person with pEPSS 0.2%CVE-2026-73409MEDIUMBudibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFileEPSS 0.2%CVE-2025-68164LOWIn JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection testEPSS 0.2%CVE-2026-59502MEDIUMPriority - CWE-203: Observable DiscrepancyEPSS 0.2%CVE-2026-11754MEDIUMUser Enumeration in Seres Software's syWEBEPSS 0.2%CVE-2024-50102MEDIUMx86: fix user address masking non-canonical speculation issueEPSS 0.2%CVE-2023-27931MEDIUMThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.3, iOS 16.4 and iPaEPSS 0.2%CVE-2025-24391MEDIUMPossible user enumerationEPSS 0.2%CVE-2026-91725MEDIUMObservable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted EPSS 0.2%CVE-2026-11284MEDIUMSide-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin dEPSS 0.2%CVE-2026-87620MEDIUMObservable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafteEPSS 0.2%CVE-2026-91714MEDIUMObservable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensEPSS 0.2%CVE-2026-87623MEDIUMObservable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensEPSS 0.2%CVE-2025-9031MEDIUMTiming-Based Username Enumeration in DivvyDrive Information Technologies' DivvyDrive WebEPSS 0.2%CVE-2026-87516MEDIUMObservable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a craftEPSS 0.2%CVE-2022-42792This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to read sensitive EPSS 0.2%CVE-2026-58445LOWCross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel APIEPSS 0.2%CVE-2025-36225MEDIUMIBM Aspera Faspex information disclosureEPSS 0.2%CVE-2025-29780MEDIUMPost-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix OperationsEPSS 0.2%CVE-2022-0823MEDIUMAn improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the passworEPSS 0.2%