Weaknesses of type CWE-294

213 results

Exposição de informação sensível a usuário não autorizado

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves API) para alguém que não deveria ter acesso. Isso ocorre por falha de controle de acesso, logging inadequado, erro em configuração ou vazamento em comunicação desprotegida. O risco é direto: credenciais ou dados privados caem em mãos erradas.

Example

Um endpoint de API retorna o hash de senha do usuário na resposta JSON, ou um arquivo de configuração com credenciais de banco de dados fica acessível publicamente no repositório git, ou um log de erro exibe o token de autenticação completo na tela do usuário final.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC/ABAC); nunca exponha segredos em respostas HTTP, logs ou versionamento; use variáveis de ambiente para credenciais; valide e sanitize erros antes de retornar ao cliente; revise regularmente permissões de arquivos e endpoints.

CVE-2022-37011A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All veEPSS 1.2%CVE-2022-42731HIGHmfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a uEPSS 1.1%CVE-2026-69676HIGHWindows Kerberos Remote Code Execution VulnerabilityEPSS 1.1%CVE-2022-29878HIGHA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent duriEPSS 1.1%CVE-2020-10045A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An error EPSS 1.1%CVE-2020-25660A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients coEPSS 1.0%CVE-2020-5300MEDIUMDisallow replay of `private_key_jwt` by blacklisting JTIs in HydraEPSS 1.0%CVE-2021-38459HIGHAUVESY VersiondogEPSS 1.0%CVE-2020-14302A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endEPSS 1.0%CVE-2020-4042MEDIUMAuthentication bypass in BareosEPSS 1.0%CVE-2024-29851HIGHVeeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.EPSS 0.9%CVE-2025-49752CRITICALAzure Bastion Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-1886HIGHAuthentication Bypass by Capture-replay in thorsten/phpmyfaqEPSS 0.9%CVE-2019-13533HIGHIn Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the contrEPSS 0.9%CVE-2021-27289CRITICALA replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = EPSS 0.9%CVE-2022-36089HIGHVelaUX APIServer vulnerable to Authentication Bypass by Capture-replayEPSS 0.9%CVE-2021-27662HIGHKT-1 Capture-replayEPSS 0.8%CVE-2023-1537MEDIUMAuthentication Bypass by Capture-replay in answerdev/answerEPSS 0.8%CVE-2022-31158HIGHAuthentication Bypass by Capture-replay in packbackbooks/lti-1-3-php-libraryEPSS 0.8%CVE-2022-22936HIGHAn issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible tEPSS 0.8%