Weaknesses of type CWE-294

213 results

Exposição de informação sensível a usuário não autorizado

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves API) para alguém que não deveria ter acesso. Isso ocorre por falha de controle de acesso, logging inadequado, erro em configuração ou vazamento em comunicação desprotegida. O risco é direto: credenciais ou dados privados caem em mãos erradas.

Example

Um endpoint de API retorna o hash de senha do usuário na resposta JSON, ou um arquivo de configuração com credenciais de banco de dados fica acessível publicamente no repositório git, ou um log de erro exibe o token de autenticação completo na tela do usuário final.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC/ABAC); nunca exponha segredos em respostas HTTP, logs ou versionamento; use variáveis de ambiente para credenciais; valide e sanitize erros antes de retornar ao cliente; revise regularmente permissões de arquivos e endpoints.

CVE-2024-38438CRITICALD-Link - CWE-294: Authentication Bypass by Capture-replayEPSS 0.7%CVE-2024-29901MEDIUM@workos-inc/authkit-nextjs session replay vulnerabilityEPSS 0.7%CVE-2023-47435CRITICALAn issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected EPSS 0.6%CVE-2023-39547CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleEPSS 0.6%CVE-2024-40715HIGHA vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypasEPSS 0.6%CVE-2024-45244MEDIUMHyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.EPSS 0.6%CVE-2021-38827HIGHXiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover.EPSS 0.6%CVE-2022-29475MEDIUMAn information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9EPSS 0.6%CVE-2023-29158MEDIUMSUBNET PowerSYSTEM Center Authentication Bypass by Capture-replayEPSS 0.6%CVE-2025-26201CRITICALCredential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentEPSS 0.6%CVE-2026-87119HIGHmpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayedEPSS 0.6%CVE-2022-2780HIGHIn affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB requesEPSS 0.6%CVE-2025-30072HIGHTiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities withEPSS 0.6%CVE-2026-55250HIGHMaravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged CachesEPSS 0.6%CVE-2026-57574HIGHMisskey: TOTP tokens can be reusedEPSS 0.6%CVE-2024-49595HIGHDell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged EPSS 0.5%CVE-2025-9100MEDIUMzhenfeng13 My-Blog Frontend Blog Article Comment comment authentication replayEPSS 0.5%CVE-2025-6533MEDIUMxxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replayEPSS 0.5%CVE-2026-51597CRITICALMERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent netEPSS 0.5%CVE-2022-47930MEDIUMAn issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implemenEPSS 0.5%