Weaknesses of type CWE-203

350 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2024-40490HIGHAn issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot PassEPSS 0.5%CVE-2026-64713HIGHThis issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, viEPSS 0.5%CVE-2024-2464MEDIUMApplication users enumeration in CDeXEPSS 0.5%CVE-2026-26315MEDIUMGo Ethereum Improperly Validates the ECIES Public Key in RLPx HandshakeEPSS 0.5%CVE-2026-56339HIGHCapgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPCEPSS 0.5%CVE-2022-4025MEDIUMInappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an EPSS 0.5%CVE-2023-33518MEDIUMemoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory pEPSS 0.5%CVE-2024-41335HIGHDraytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior EPSS 0.5%CVE-2024-11084MEDIUMPotential Username Enumeration in Helix ALMEPSS 0.5%CVE-2023-28015MEDIUMHCL Domino AppDev Pack is susceptible to a User Account Enumeration vulnerabilityEPSS 0.4%CVE-2023-34344MEDIUMA vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid usernameEPSS 0.4%CVE-2024-31878MEDIUMIBM i information disclosureEPSS 0.4%CVE-2023-1696HIGHThe multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability.EPSS 0.4%CVE-2024-21206MEDIUMVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versEPSS 0.4%CVE-2026-78955MEDIUMObservable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origEPSS 0.4%CVE-2024-12663MEDIUMfunnyzpc Mee-Admin Login login observable response discrepancyEPSS 0.4%CVE-2024-28885HIGHObservable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network aEPSS 0.4%CVE-2026-47379MEDIUMNocoDB: Plaintext Password Comparison in Shared ViewsEPSS 0.4%CVE-2024-39921HIGHObservable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to VEPSS 0.4%CVE-2026-64822MEDIUMdjangoSIGE 1.10 User Enumeration via ForgotPasswordViewEPSS 0.4%