Weaknesses of type CWE-204

188 results

Vazamento de informações através de respostas diferenciadas

A aplicação retorna respostas diferentes (tempo de processamento, mensagens de erro, código HTTP, tamanho da resposta) dependendo do estado interno do sistema, permitindo que atacantes deduzam informações sensíveis sem autorização. Por exemplo, responder com 'usuário não encontrado' versus 'senha incorreta' vaza a existência de contas.

Example

Um formulário de login que retorna 'usuário inexistente' para um email não cadastrado, mas 'credenciais inválidas' quando o email existe, permite que invasores enumerem contas válidas da plataforma sem precisar quebrar senhas.

How to mitigate

Padronize todas as respostas de erro (mensagens e tempo de processamento) para cenários de falha similares. Use mensagens genéricas como 'credenciais inválidas' independente do motivo real, e implemente rate limiting para dificultar enumeração automatizada.

CVE-2021-36201MEDIUMCCURE Observable Response DiscrepancyEPSS 0.6%CVE-2024-40627MEDIUMOpaMiddleware does not filter HTTP OPTIONS requestsEPSS 0.6%CVE-2023-41885MEDIUMPiccolo's current `BaseUser.login` implementation is vulnerable to time based user enumerationEPSS 0.6%CVE-2023-32346MEDIUM Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function reEPSS 0.5%CVE-2025-24980MEDIUMPimcore Admin Classic Bundle allows user enumerationEPSS 0.5%CVE-2025-31124MEDIUMZitadel allows User Enumeration by loginname attribute normalizationEPSS 0.5%CVE-2023-23584MEDIUM An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence oEPSS 0.5%CVE-2025-54834MEDIUMOPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumerationEPSS 0.5%CVE-2024-1145MEDIUMObservable Response Discrepancy at Alma Devklan BlogEPSS 0.5%CVE-2023-28412MEDIUM When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of dEPSS 0.5%CVE-2023-27283MEDIUMIBM Aspera Orchestrator information disclosureEPSS 0.5%CVE-2023-38362MEDIUMIBM CICS TX information disclosureEPSS 0.5%CVE-2026-66002MEDIUMFrappe: User Enumeration via PDDREPSS 0.5%CVE-2024-51447MEDIUMA vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of tEPSS 0.5%CVE-2021-20556MEDIUMIBM Cognos Controller information disclosureEPSS 0.5%CVE-2023-37831—An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentEPSS 0.5%CVE-2023-27464MEDIUMA vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix EPSS 0.5%CVE-2025-40806MEDIUMA vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeratioEPSS 0.5%CVE-2023-4095MEDIUMUser enumeration vulnerability in Fujitsu Arconte ÁureaEPSS 0.5%CVE-2025-30280MEDIUMA vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), MendiEPSS 0.5%