Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2026-20312HIGHCisco Catalyst SD-WAN Security Hardening Release - Information Disclosure VulnerabilitiesEPSS 0.3%CVE-2024-7259MEDIUMOvirt-engine: potential exposure of cleartext provider passwords via web uiEPSS 0.3%CVE-2025-10464MEDIUMCleartext password storage in Birtech Information Technologies' SensawayEPSS 0.3%CVE-2025-54538MEDIUMIn JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" commandEPSS 0.3%CVE-2025-54537MEDIUMIn JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshotsEPSS 0.3%CVE-2021-33716—A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1EPSS 0.3%CVE-2025-46633HIGHCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt EPSS 0.3%CVE-2023-3950MEDIUMCleartext Storage of Sensitive Information in GitLabEPSS 0.3%CVE-2024-45862HIGHCleartext Storage of Sensitive Information in Kastle Systems Access Control SystemEPSS 0.2%CVE-2023-48305MEDIUMNextcloud Server user_ldap app logs user passwords in the log file on level debugEPSS 0.2%CVE-2026-63406MEDIUMAnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including SecretsEPSS 0.2%CVE-2025-65320HIGHAbacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The applicatEPSS 0.2%CVE-2025-63208HIGHAn issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive EPSS 0.2%CVE-2023-41964MEDIUMBIG-IP and BIG-IQ Database Variable vulnerabilityEPSS 0.2%CVE-2023-31925MEDIUMStorage of clear text password in Brocade SANnavEPSS 0.2%CVE-2024-6921HIGHCleartext Username and Password in NAC Telecommunication's NACPremiumEPSS 0.2%CVE-2025-55443CRITICALTelpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stEPSS 0.2%CVE-2022-47512MEDIUMSensitive Data Disclosure VulnerabilityEPSS 0.2%CVE-2025-65278HIGHAn issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive iEPSS 0.2%CVE-2018-19009—Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti EPSS 0.2%