Weaknesses of type CWE-209

427 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2024-13538MEDIUMBigBuy Dropshipping Connector for WooCommerce <= 2.0.0 - Unauthenticated Full Path DisclosuteEPSS 0.6%CVE-2023-46240HIGHCodeIgniter4 vulnerable to information disclosure when detailed error report is displayed in production environmentEPSS 0.6%CVE-2022-38107MEDIUMSensitive Data Disclosure VulnerabilityEPSS 0.6%CVE-2024-2009MEDIUMNway Pro Argument index.php ajax_login_submit_form information exposureEPSS 0.6%CVE-2024-35155MEDIUMIBM MQ information disclosureEPSS 0.6%CVE-2022-33930MEDIUMDell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit thiEPSS 0.6%CVE-2023-1210LOWGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.6%CVE-2025-9005MEDIUMmtons mblog register information exposureEPSS 0.6%CVE-2024-22646MEDIUMAn email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to gueEPSS 0.6%CVE-2024-54366MEDIUMWordPress Vimeography plugin <= 2.4.4 - Full Path Disclosure (FPD) vulnerabilityEPSS 0.6%CVE-2023-47152MEDIUMIBM Db2 information disclosureEPSS 0.6%CVE-2026-56139MEDIUMApache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clientsEPSS 0.6%CVE-2026-49365MEDIUMApache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clientsEPSS 0.6%CVE-2025-44203HIGHIn HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs EPSS 0.6%CVE-2023-48393MEDIUMKaifa Technology WebITR - Error Message LeakageEPSS 0.6%CVE-2024-25037MEDIUMIBM Cognos Controller information disclosureEPSS 0.6%CVE-2024-12380MEDIUMGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.6%CVE-2023-6944MEDIUMRhdh: catalog-import function leaks credentials to frontendEPSS 0.6%CVE-2024-6980CRITICALVerbose error handling issue in GravityZone Update Server proxy serviceEPSS 0.6%CVE-2023-3362MEDIUMGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.5%