Weaknesses of type CWE-294

213 results

Exposição de informação sensível a usuário não autorizado

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves API) para alguém que não deveria ter acesso. Isso ocorre por falha de controle de acesso, logging inadequado, erro em configuração ou vazamento em comunicação desprotegida. O risco é direto: credenciais ou dados privados caem em mãos erradas.

Example

Um endpoint de API retorna o hash de senha do usuário na resposta JSON, ou um arquivo de configuração com credenciais de banco de dados fica acessível publicamente no repositório git, ou um log de erro exibe o token de autenticação completo na tela do usuário final.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC/ABAC); nunca exponha segredos em respostas HTTP, logs ou versionamento; use variáveis de ambiente para credenciais; valide e sanitize erros antes de retornar ao cliente; revise regularmente permissões de arquivos e endpoints.

CVE-2022-40621WAVLINK Quantum D4G (WN531G3) Pass-The-HashEPSS 0.8%CVE-2024-29850HIGHVeeam Backup Enterprise Manager allows account takeover via NTLM relay.EPSS 0.8%CVE-2026-65905CRITICALApache Tomcat: Limited replay attack possible with DIGEST authenticationEPSS 0.8%CVE-2025-30201HIGHWazuh NetNTLMv2 Hash Theft In Multiple Centralized Configuration CapabilitiesEPSS 0.8%CVE-2023-6374MEDIUMAuthentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all serial numbers aEPSS 0.8%CVE-2018-19023Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized rEPSS 0.8%CVE-2023-41890HIGHSustainsys.Saml2 Insufficient Identity Provider Issuer ValidationEPSS 0.8%CVE-2022-44457CRITICALA vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All veEPSS 0.7%CVE-2022-45914MEDIUMThe ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 boaEPSS 0.7%CVE-2026-16083MEDIUMSipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replayEPSS 0.7%CVE-2018-14781MEDIUMMedtronic MiniMed MMT-500/MMT-503 Remote Controllers Authentication Bypass by Capture-replayEPSS 0.7%CVE-2024-34065HIGH@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassEPSS 0.7%CVE-2024-12839HIGHChanging Information Technology CGFIDO - Authentication BypassEPSS 0.7%CVE-2023-0014CRITICALCapture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.7%CVE-2022-38766HIGHThe remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open requesEPSS 0.7%CVE-2026-47341MEDIUMApache APISIX: Session replay issue in hmac-authEPSS 0.7%CVE-2026-11856CRITICALcross-origin Digest auth state leakEPSS 0.7%CVE-2025-6029CRITICALKIA-branded Aftermarket Generic Smart Keyless Entry System Replay AttackEPSS 0.7%CVE-2026-28564CRITICALApache IoTDB: REST Basic Authentication Accepts Stale Cached CredentialsEPSS 0.7%CVE-2018-17935All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. ThisEPSS 0.7%