Weaknesses of type CWE-223

12 results

Omissão de informações relevantes à segurança

A aplicação falha em registrar, reportar ou comunicar informações críticas para a segurança — como tentativas de acesso não autorizadas, erros de autenticação ou operações sensíveis. Sem esses dados, ataques passam despercebidos e investigações forenses ficam impossíveis.

Example

Um sistema de login que não registra falhas de autenticação repetidas, permitindo força bruta silenciosa. Ou uma API que não loga quem acessou dados sensíveis — quando há vazamento, ninguém descobre quem fez.

How to mitigate

Implemente logging estruturado de todos os eventos de segurança (autenticação, autorização, acesso a dados sensíveis, mudanças críticas). Garanta que logs sejam enviados a um sistema centralizado com retenção adequada e alertas para anomalias.

CVE-2023-28360MEDIUMAn omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file tEPSS 0.8%CVE-2024-52813MEDIUMmatrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identityEPSS 0.5%CVE-2026-91859MEDIUMMISP Access Log Entry Overwritten by Error Controller's Second beforeFilter PassEPSS 0.5%CVE-2022-44646LOWIn JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settingsEPSS 0.4%CVE-2023-31191CRITICALDenial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark InnovationsEPSS 0.4%CVE-2023-29156MEDIUMDenial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark InnovationsEPSS 0.3%CVE-2022-22563MEDIUMDell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vuEPSS 0.2%CVE-2025-52926LOWIn scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface.EPSS 0.2%CVE-2026-90955MEDIUMMISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model LoadEPSS 0.2%CVE-2026-31890MEDIUMInspektor Gadget: Tracing Denial of Service via Event FloodingEPSS 0.1%CVE-2026-49426LOWIncorrect audit records for ptrace(2) syscall requestsEPSS 0.1%CVE-2025-35987MEDIUMOmission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: KernEPSS 0.1%