Weaknesses of type CWE-212

78 results

Divulgação de Informações

Fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, chaves, dados pessoais) a usuários não autorizados ou em contextos onde não deveria. O risco é que informações confidenciais se tornem acessíveis, comprometendo confidencialidade e facilitando ataques subsequentes.

Example

Uma API retorna mensagens de erro com stack traces completos contendo caminhos de arquivo e nomes de variáveis internas; ou um arquivo de configuração é deixado publicamente acessível e expõe credenciais de banco de dados; ou cookies de sessão são transmitidos sem HTTPS.

How to mitigate

Implemente controle de acesso rigoroso e valide permissões antes de expor dados. Trate erros de forma genérica para o usuário final, registre detalhes apenas em logs do servidor. Use HTTPS, marque cookies com flags `HttpOnly` e `Secure`, e revise regularmente o que está sendo exposto via APIs, logs e páginas de erro.

CVE-2026-67071MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or TransferEPSS 0.2%CVE-2025-65000LOWExposure of SSH Private Keys in Remote Alert Handlers (Linux) RuleEPSS 0.2%CVE-2026-86740MEDIUMSnipe-IT before 8.7.0 Attachment Deletion Reports Success While File RemainsEPSS 0.2%CVE-2026-34214HIGHTrino: Iceberg REST catalog static and vended credentials are accessible via query JSONEPSS 0.2%CVE-2025-24884MEDIUMkube-audit-rest's example logging configuration could disclose secret values in the audit logEPSS 0.2%CVE-2026-1182MEDIUMImproper Removal of Sensitive Information Before Storage or Transfer in GitLabEPSS 0.2%CVE-2025-64326LOWWeblate leaks the IP of project members inviting users to assume reviewer roles in Audit logEPSS 0.2%CVE-2025-0011LOWImproper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address EPSS 0.2%CVE-2026-90860HIGHThe Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebVieEPSS 0.2%CVE-2026-32891CRITICALAnchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSEPSS 0.2%CVE-2025-20118MEDIUMCisco Application Policy Infrastructure Controller Authenticated Command Injection Due to Sensitive Disclosure VulnerabilityEPSS 0.2%CVE-2025-8860LOWQemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callbackEPSS 0.2%CVE-2025-65965HIGHGrype has a credential disclosure vulnerability in Grype JSON outputEPSS 0.1%CVE-2026-36178MEDIUMThe factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, poEPSS 0.1%CVE-2026-53604HIGHnebula-mesh: CA private key not zeroized on web mobile-bundle error pathsEPSS 0.1%CVE-2026-45046MEDIUMGryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive ContentEPSS 0.1%CVE-2024-5300MEDIUMAppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbdEPSS 0.1%CVE-2026-15811MEDIUMKronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changesEPSS 0.1%