Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2026-43824HIGHIn Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.EPSS 0.2%CVE-2024-8689MEDIUMActiveMQ Content Pack: Cleartext Exposure of CredentialsEPSS 0.2%CVE-2024-45744LOWTopQuadrant TopBraid EDG password manager stores external credentials insecurelyEPSS 0.2%CVE-2023-28912MEDIUMCleartext Phonebook InformationEPSS 0.2%CVE-2024-31587MEDIUMSecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a EPSS 0.2%CVE-2020-7517—A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow EPSS 0.2%CVE-2026-86280MEDIUMSourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storageEPSS 0.2%CVE-2025-7738MEDIUMPython3.11-django-ansible-base: sensitive authenticator secrets returned in clear text via api in aapEPSS 0.2%CVE-2024-36589MEDIUMAn issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd81EPSS 0.2%CVE-2020-25677—A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allowEPSS 0.2%CVE-2025-1499MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.2%CVE-2026-61928MEDIUMWindows Hello Tampering VulnerabilityEPSS 0.2%CVE-2024-35117MEDIUMIBM OpenPages with Watson information disclosureEPSS 0.2%CVE-2024-24488MEDIUMAn issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password cEPSS 0.2%CVE-2025-53742MEDIUMJenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, EPSS 0.2%CVE-2026-32842HIGHEdimax GS-5008PL <= 1.00.54 Admin Credentials Stored in CleartextEPSS 0.2%CVE-2026-41385HIGHOpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction BypassEPSS 0.2%CVE-2022-39351MEDIUMDependency-Track vulnerable to logging of API keys in clear text when handling API requests using keys with insufficient permissionsEPSS 0.2%CVE-2021-22509HIGHHandling of sensitive data in process memory in NetIQ Advance AuthenticationEPSS 0.2%CVE-2026-59657HIGHApache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJobEPSS 0.2%