Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2025-44614HIGHTinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plEPSS 0.2%CVE-2025-49728MEDIUMMicrosoft PC Manager Security Feature Bypass VulnerabilityEPSS 0.2%CVE-2025-44649HIGHIn the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive modEPSS 0.2%CVE-2024-33470MEDIUMAn issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passbacEPSS 0.2%CVE-2019-14890HIGHA vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentiEPSS 0.2%CVE-2025-12680MEDIUMBrocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680)EPSS 0.2%CVE-2026-13380CRITICALVSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP ResponsesEPSS 0.2%CVE-2026-33512HIGHAVideo has an unauthenticated decrypt oracle leaking any ciphertextEPSS 0.2%CVE-2025-25613HIGHFS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 wEPSS 0.2%CVE-2024-9798MEDIUMHealth endpoint offers list of onboarded services to unauthenticated usersEPSS 0.2%CVE-2024-28065MEDIUMIn Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.EPSS 0.2%CVE-2023-31423MEDIUMPossible information exposure through log file vulnerabilityEPSS 0.2%CVE-2026-59244MEDIUMApache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UIEPSS 0.2%CVE-2026-68970MEDIUMApache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UIEPSS 0.2%CVE-2024-52284HIGHRancher Fleet Helm Values are stored inside BundleDeployment in plain textEPSS 0.2%CVE-2023-24442MEDIUMJenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar pEPSS 0.2%CVE-2024-28810MEDIUMAn issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allowsEPSS 0.2%CVE-2024-21993MEDIUMInformation Disclosure Vulnerability in SnapCenterEPSS 0.2%CVE-2019-25279MEDIUMFaceSentry Access Control System 6.4.8 Cleartext Password Storage VulnerabilityEPSS 0.2%CVE-2026-43824HIGHIn Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.EPSS 0.2%