Weaknesses of type CWE-212

78 results

Divulgação de Informações

Fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, chaves, dados pessoais) a usuários não autorizados ou em contextos onde não deveria. O risco é que informações confidenciais se tornem acessíveis, comprometendo confidencialidade e facilitando ataques subsequentes.

Example

Uma API retorna mensagens de erro com stack traces completos contendo caminhos de arquivo e nomes de variáveis internas; ou um arquivo de configuração é deixado publicamente acessível e expõe credenciais de banco de dados; ou cookies de sessão são transmitidos sem HTTPS.

How to mitigate

Implemente controle de acesso rigoroso e valide permissões antes de expor dados. Trate erros de forma genérica para o usuário final, registre detalhes apenas em logs do servidor. Use HTTPS, marque cookies com flags `HttpOnly` e `Secure`, e revise regularmente o que está sendo exposto via APIs, logs e páginas de erro.

CVE-2026-62900MEDIUM.NET Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-31493MEDIUMAn improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 anEPSS 0.5%CVE-2026-45737MEDIUMArgo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotationsEPSS 0.5%CVE-2026-42880CRITICALArgoCD ServerSideDiff is vulnerable to Kubernetes Secret ExtractionEPSS 0.5%CVE-2025-27221LOWIn the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication crEPSS 0.5%CVE-2024-6055MEDIUMImproper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on WinEPSS 0.5%CVE-2026-40895MEDIUMfollow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect TargetsEPSS 0.5%CVE-2025-68131MEDIUMCBORDecoder reuse can leak shareable values across decode callsEPSS 0.5%CVE-2026-20928MEDIUMWindows Recovery Environment Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2025-53886MEDIUMDirectus doesn't redact tokens in Flow logsEPSS 0.4%CVE-2025-14267MEDIUMUnintended temporary cached data included in a structure only copy intended to be empty of dataEPSS 0.4%CVE-2024-41156LOWProfile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers vaEPSS 0.4%CVE-2025-58049MEDIUMXWiki PDF export jobs store sensitive cookies unencrypted in job statusesEPSS 0.4%CVE-2024-43384HIGHPhoenix Contact: Improper removal of sensitive information in MGUARD productsEPSS 0.3%CVE-2023-52376HIGHInformation management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.3%CVE-2026-43528HIGHOpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig AliasesEPSS 0.3%CVE-2020-25635MEDIUMA flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is compleEPSS 0.3%CVE-2025-48708MEDIUMgs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A createEPSS 0.3%CVE-2024-56353MEDIUMIn JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookiesEPSS 0.3%CVE-2022-23605MEDIUMExpired Ephemeral Messages not reliably removed in wire-webappEPSS 0.3%