Weaknesses of type CWE-203

350 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2026-47011LOWVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affEPSS 0.2%CVE-2026-87566MEDIUMObservable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a craftEPSS 0.2%CVE-2026-79181MEDIUMObservable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a craftEPSS 0.2%CVE-2026-59640HIGHOpenPGP CFB quick-check oracle active on symmetric/session-key pathsEPSS 0.2%CVE-2025-46804LOWScreen 5.0.0 and older versions allow file existence tests when installed setuid-rootEPSS 0.2%CVE-2025-13166LOWUsername Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account DiscoveryEPSS 0.2%CVE-2026-87539LOWObservable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafteEPSS 0.2%CVE-2018-9364HIGHIn the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure booEPSS 0.2%CVE-2026-45294MEDIUMFreeScout: User Account Enumeration via Password Reset Response DifferentiationEPSS 0.2%CVE-2024-23984MEDIUMObservable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosuEPSS 0.2%CVE-2026-33425MEDIUMDiscourse has inferable private group membership or existence via exclude_groups parameterEPSS 0.2%CVE-2024-27839MEDIUMA privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicioEPSS 0.2%CVE-2026-45410MEDIUMTime-based user enumeration in TREK authentication endpointEPSS 0.2%CVE-2026-72699CRITICALGrav Login Plugin before 3.9.1 Email Enumeration via RegistrationEPSS 0.2%CVE-2026-73630MEDIUMSiYuan before v3.7.4 Information Disclosure via authFilePublishAccessEPSS 0.2%CVE-2026-11289MEDIUMSide-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a EPSS 0.2%CVE-2026-55227MEDIUMObservable object existence disclosure in private Weblate projects via globally scoped object lookupsEPSS 0.2%CVE-2025-54999LOWOpenBao: Timing Side-Channel in Userpass Auth MethodEPSS 0.2%CVE-2026-87619MEDIUMObservable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a craftedEPSS 0.2%CVE-2026-23620MEDIUMGFI MailEssentials AI < 22.4 ListServer.IsDBExist() Absolute Directory Traversal to File EnumerationEPSS 0.2%