Weaknesses of type CWE-204

188 results

Vazamento de informações através de respostas diferenciadas

A aplicação retorna respostas diferentes (tempo de processamento, mensagens de erro, código HTTP, tamanho da resposta) dependendo do estado interno do sistema, permitindo que atacantes deduzam informações sensíveis sem autorização. Por exemplo, responder com 'usuário não encontrado' versus 'senha incorreta' vaza a existência de contas.

Example

Um formulário de login que retorna 'usuário inexistente' para um email não cadastrado, mas 'credenciais inválidas' quando o email existe, permite que invasores enumerem contas válidas da plataforma sem precisar quebrar senhas.

How to mitigate

Padronize todas as respostas de erro (mensagens e tempo de processamento) para cenários de falha similares. Use mensagens genéricas como 'credenciais inválidas' independente do motivo real, e implemente rate limiting para dificultar enumeração automatizada.

CVE-2024-28868LOWUmbraco possible user enumeration vulnerabilityEPSS 0.5%CVE-2023-46170MEDIUMIBM DS8900F information disclosureEPSS 0.5%CVE-2023-37217MEDIUM Tadiran Telecom Aeonix - CWE-204: Observable Response DiscrepancyEPSS 0.4%CVE-2023-31186MEDIUMAvaya IX Workforce Engagement - User Enumeration - CWE-204: Observable Response DiscrepancyEPSS 0.4%CVE-2023-40179MEDIUMSilverware Games vulnerable to account enumeration via inconsistent responsesEPSS 0.4%CVE-2024-55198MEDIUMUser Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allowEPSS 0.4%CVE-2024-12663MEDIUMfunnyzpc Mee-Admin Login login observable response discrepancyEPSS 0.4%CVE-2025-62181MEDIUMPega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration where during user authentication process, a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.EPSS 0.4%CVE-2023-49069MEDIUMA vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by theEPSS 0.4%CVE-2026-33419CRITICALMinIO: LDAP login brute-force via user enumeration and missing rate limitEPSS 0.4%CVE-2025-3092HIGHMB connect line: Observable response discrepancy in mbCONNECT24/mymbCONNECT24EPSS 0.4%CVE-2026-61503MEDIUMRejetto HFS < 3.2.1 Username Enumeration via Login Response DifferencesEPSS 0.4%CVE-2018-25350CRITICALuserSpice 4.3.24 Username Enumeration via existingUsernameCheck.phpEPSS 0.4%CVE-2026-54739MEDIUMLemmy: Login Endpoint User Enumeration via HTTP Response Code DifferentialEPSS 0.4%CVE-2025-5485HIGHSinoTrack GPS Receiver Weak AuthenticationEPSS 0.4%CVE-2024-8651MEDIUMNetcat CMS: user enumerationEPSS 0.4%CVE-2019-25338MEDIUMDokuwiki 2018-04-22b - Username EnumerationEPSS 0.4%CVE-2025-24342MEDIUMA vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernaEPSS 0.4%CVE-2026-73306MEDIUMBudibase: Account Enumeration via Login Lockout Response DifferentialEPSS 0.4%CVE-2024-38322MEDIUMIBM Storage Defender information disclosureEPSS 0.4%