Weaknesses of type CWE-203

350 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2023-26560MEDIUMNorthern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbEPSS 0.5%CVE-2023-6935MEDIUMMarvin Attack vulnerability in SP Math All RSAEPSS 0.5%CVE-2021-45925MEDIUMUsername EnumerationEPSS 0.5%CVE-2022-43412MEDIUMJenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided anEPSS 0.5%CVE-2024-26268MEDIUMUser enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 2EPSS 0.5%CVE-2023-3529MEDIUMRotem Dynamics Rotem CRM OTP URI Interface information exposureEPSS 0.5%CVE-2026-44332MEDIUMFiber: Username Enumeration via Timing Oracle in BasicAuth Default AuthorizerEPSS 0.5%CVE-2023-24598OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the privEPSS 0.5%CVE-2025-31124MEDIUMZitadel allows User Enumeration by loginname attribute normalizationEPSS 0.5%CVE-2023-43623MEDIUMA vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (MendixEPSS 0.5%CVE-2021-46876MEDIUMAn issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existenceEPSS 0.5%CVE-2023-37482MEDIUMThe login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated reEPSS 0.5%CVE-2023-22359MEDIUMUser-enumeration in RestAPIEPSS 0.5%CVE-2023-36325LOWi2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attEPSS 0.5%CVE-2022-26382MEDIUMWhile the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel atEPSS 0.5%CVE-2023-54357HIGHJoomla com_booking 2.4.9 Information Disclosure via Account EnumerationEPSS 0.5%CVE-2024-0436HIGHPrevent timing attack for single-user password checkEPSS 0.5%CVE-2019-19338MEDIUMA flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculativEPSS 0.5%CVE-2024-25651MEDIUMUser enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whetEPSS 0.5%CVE-2024-49358MEDIUMZimaOS vulnerable to Username Enumeration via API ResponsesEPSS 0.5%