Weaknesses of type CWE-203

350 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2024-13198MEDIUMlanghsu Mblog Blog System login observable response discrepancyEPSS 0.7%CVE-2025-21510HIGHVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are EPSS 0.7%CVE-2023-25728MEDIUMThe <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interactionEPSS 0.7%CVE-2022-45416MEDIUMKeyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as PriEPSS 0.7%CVE-2022-40084MEDIUMOpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a passEPSS 0.7%CVE-2023-26215HIGHTIBCO EBX® Add-ons Path TraversalEPSS 0.7%CVE-2025-27667CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email EnumeratiEPSS 0.7%CVE-2023-27870MEDIUMIBM Spectrum Virtualize information disclosureEPSS 0.7%CVE-2023-26071HIGHAn issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In EPSS 0.7%CVE-2022-44381MEDIUMSnipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.EPSS 0.6%CVE-2022-41765MEDIUMAn issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes theEPSS 0.6%CVE-2022-35888MEDIUMAmpere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extractEPSS 0.6%CVE-2024-41952MEDIUMZitadel has an "Ignoring unknown usernames" vulnerabilityEPSS 0.6%CVE-2025-21336MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-43546MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-47102MEDIUMUrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.EPSS 0.6%CVE-2024-0564MEDIUMKernel: max page sharing of kernel samepage merging (ksm) may cause memory deduplicationEPSS 0.6%CVE-2023-39522MEDIUMUsername enumeration attack in goauthentikEPSS 0.6%CVE-2023-52323MEDIUMPyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.EPSS 0.6%CVE-2026-51926HIGHAn issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerEPSS 0.6%