Weaknesses of type CWE-204

191 results

Vazamento de informações através de respostas diferenciadas

A aplicação retorna respostas diferentes (tempo de processamento, mensagens de erro, código HTTP, tamanho da resposta) dependendo do estado interno do sistema, permitindo que atacantes deduzam informações sensíveis sem autorização. Por exemplo, responder com 'usuário não encontrado' versus 'senha incorreta' vaza a existência de contas.

Example

Um formulário de login que retorna 'usuário inexistente' para um email não cadastrado, mas 'credenciais inválidas' quando o email existe, permite que invasores enumerem contas válidas da plataforma sem precisar quebrar senhas.

How to mitigate

Padronize todas as respostas de erro (mensagens e tempo de processamento) para cenários de falha similares. Use mensagens genéricas como 'credenciais inválidas' independente do motivo real, e implemente rate limiting para dificultar enumeração automatizada.

CVE-2025-66307MEDIUMGrav Admin Plugin vulnerable to User Enumeration & Email DisclosureEPSS 0.3%CVE-2025-3939MEDIUMObservable Response DiscrepancyEPSS 0.3%CVE-2026-27462HIGHCombodo iTop: User enumeration via password resetEPSS 0.3%CVE-2025-46390HIGHCWE-204: Observable Response DiscrepancyEPSS 0.3%CVE-2025-58442MEDIUMSaleor has user enumeration vulnerability due to different error messagesEPSS 0.3%CVE-2025-62236MEDIUMFrontier Airlines publicly available email address validationEPSS 0.3%CVE-2024-56476MEDIUMIBM TXSeries for Multiplatforms information disclosureEPSS 0.3%CVE-2026-47083MEDIUMAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH comEPSS 0.3%CVE-2026-19080HIGHUsername Enumeration in Menulux Software's Menulux PortalEPSS 0.3%CVE-2025-12455MEDIUMUsername Enumeration Observable Response Discrepancy vulnerability has been discovered in OpenText™ Vertica.EPSS 0.3%CVE-2023-37413MEDIUMIBM Aspera Faspex information disclosureEPSS 0.3%CVE-2025-12994MEDIUMMedtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that coEPSS 0.3%CVE-2026-26744MEDIUMA user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpEPSS 0.3%CVE-2026-24468MEDIUMOpenAEV Vulnerable to Username/Email Enumeration Through Differential HTTP Responses in Password Reset APIEPSS 0.3%CVE-2026-24332MEDIUMDiscord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because EPSS 0.3%CVE-2026-84307LOWFilament: Password validity disclosure for accounts denied panel access on login pageEPSS 0.3%CVE-2026-54445MEDIUMVantage6: Set admin user and password from environment or configurationEPSS 0.3%CVE-2025-52899MEDIUMTuleap vulnerable to user enumeration via the lost password formEPSS 0.3%CVE-2026-4045MEDIUMprojectsend Auth.php response discrepancyEPSS 0.3%CVE-2026-8242MEDIUMIndustrial Application Software IAS Canias ERP Login RMI doAction response discrepancyEPSS 0.3%