Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2025-45001HIGHreact-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaEPSS 0.2%CVE-2026-7163MEDIUMAssisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosureEPSS 0.2%CVE-2025-59701MEDIUMEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.2%CVE-2026-35644HIGHOpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway SnapshotsEPSS 0.2%CVE-2025-14377HIGHVerve Asset Manager – Plaintext Storage VulnerabilitiesEPSS 0.2%CVE-2024-39846LOWNewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitiEPSS 0.2%CVE-2025-12774MEDIUMSQL queries with sensitive information printed in logs with Brocade SANnav before 3.0EPSS 0.2%CVE-2022-35120HIGHIXPdata EasyInstall 6.6.14725 contains an access control issue.EPSS 0.2%CVE-2025-4394MEDIUMMedtronic MyCareLink Patient Monitor Unencrypted Filesystem VulnerabilityEPSS 0.2%CVE-2024-38877HIGHA vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All verEPSS 0.2%CVE-2025-56565HIGHDD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within noEPSS 0.2%CVE-2025-46820HIGHphpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifactEPSS 0.2%CVE-2021-3551—A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log fiEPSS 0.2%CVE-2024-25658MEDIUMCleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the daEPSS 0.2%CVE-2022-24120MEDIUMCertain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.EPSS 0.2%CVE-2025-67637MEDIUMJenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins contEPSS 0.2%CVE-2026-77975HIGHEbyte NA111-M Cleartext Storage of Sensitive InformationEPSS 0.2%CVE-2025-56566MEDIUMMikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attackerEPSS 0.2%CVE-2023-49113HIGHSensitive Data Stored Insecurely in Kiuwan SAST Local AnalyzerEPSS 0.2%CVE-2021-27487—ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker toEPSS 0.2%