Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2026-59657HIGHApache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJobEPSS 0.2%CVE-2024-9802MEDIUMConformance validation endpoint discloses detail about service to unauthenticated usersEPSS 0.2%CVE-2026-5531MEDIUMSourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in fileEPSS 0.2%CVE-2026-53603HIGHnebula-mesh: Operator session tokens stored in plaintext in the databaseEPSS 0.2%CVE-2023-24454MEDIUMJenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on tEPSS 0.2%CVE-2023-24439MEDIUMJenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file onEPSS 0.2%CVE-2020-7516—A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allowEPSS 0.2%CVE-2025-14836MEDIUMZZCMS User Data Storage user_save.php cleartext storage in fileEPSS 0.2%CVE-2026-90842MEDIUMPHPGurukul Blood Donor Management System Login_Model.php cleartext storage in fileEPSS 0.2%CVE-2026-81321CRITICALCareCam CM2507 Cleartext Storage of Sensitive InformationEPSS 0.2%CVE-2025-5154MEDIUMPhonePe App SQLite Database databases cleartext storage in a file or on diskEPSS 0.2%CVE-2020-29500HIGHDell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locaEPSS 0.2%CVE-2020-29502HIGHDell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A EPSS 0.2%CVE-2026-46622HIGHSolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breachEPSS 0.2%CVE-2026-27520HIGHBinardat 10G08-0800GSM Network Switch Base64-encoded Password Stored in CookieEPSS 0.2%CVE-2024-4840MEDIUMRhosp-director: cleartext passwords exposed in logsEPSS 0.2%CVE-2022-45439MEDIUMA pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. EPSS 0.2%CVE-2026-34214HIGHTrino: Iceberg REST catalog static and vended credentials are accessible via query JSONEPSS 0.2%CVE-2026-47702CRITICALTypeBot API tokens stored in plaintextEPSS 0.2%CVE-2026-57287MEDIUMJenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying hiEPSS 0.2%