Weaknesses of type CWE-294

213 results

Exposição de informação sensível a usuário não autorizado

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves API) para alguém que não deveria ter acesso. Isso ocorre por falha de controle de acesso, logging inadequado, erro em configuração ou vazamento em comunicação desprotegida. O risco é direto: credenciais ou dados privados caem em mãos erradas.

Example

Um endpoint de API retorna o hash de senha do usuário na resposta JSON, ou um arquivo de configuração com credenciais de banco de dados fica acessível publicamente no repositório git, ou um log de erro exibe o token de autenticação completo na tela do usuário final.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC/ABAC); nunca exponha segredos em respostas HTTP, logs ou versionamento; use variáveis de ambiente para credenciais; valide e sanitize erros antes de retornar ao cliente; revise regularmente permissões de arquivos e endpoints.

CVE-2017-5251In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices areEPSS 0.5%CVE-2026-8927CRITICALenv-set cross-proxy Digest auth state leakEPSS 0.5%CVE-2020-27269In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AEPSS 0.5%CVE-2026-26232CRITICALGitea OAuth2 authorization codes lack expiry and reuse enforcementEPSS 0.5%CVE-2026-86219CRITICALAuthen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_stepEPSS 0.5%CVE-2026-20779HIGHGitea TOTP single-use enforcement defect allows OTP replayEPSS 0.5%CVE-2021-25480MEDIUMA lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead tEPSS 0.5%CVE-2026-7168MEDIUMcross-proxy Digest auth state leakEPSS 0.5%CVE-2022-44555HIGHThe DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.EPSS 0.5%CVE-2024-39081MEDIUMAn issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.EPSS 0.5%CVE-2025-46815HIGHZITADEL Allows IdP Intent Token ReuseEPSS 0.4%CVE-2026-73683CRITICALLaravel Socialite Facebook Provider Authentication Bypass via Nonce ReplayEPSS 0.4%CVE-2025-64131HIGHJenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about EPSS 0.4%CVE-2023-45794MEDIUMA vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.4.0), Mendix Applications using Mendix 7 (AllEPSS 0.4%CVE-2026-37982MEDIUMKeycloak: org.keycloak.authentication: keycloak: unauthorized account takeover via webauthn token replayEPSS 0.4%CVE-2026-54779MEDIUMCoreWCF: SAML token replay protection is inoperativeEPSS 0.4%CVE-2026-84003HIGHMicrosoft Authentication Library (MSAL) for Node.js Spoofing VulnerabilityEPSS 0.4%CVE-2026-73136HIGHStatic memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replayEPSS 0.4%CVE-2026-35149HIGHHCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.EPSS 0.4%CVE-2026-53431CRITICALBoruta accepts expired JWT client assertions due to missing exp claim validationEPSS 0.4%