Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2020-29501MEDIUMDell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A EPSS 0.2%CVE-2021-38422HIGHDelta Electronics DIALinkEPSS 0.2%CVE-2024-28809HIGHAn issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers tEPSS 0.2%CVE-2022-45154MEDIUMsupportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.shEPSS 0.2%CVE-2023-40715MEDIUMA cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access toEPSS 0.2%CVE-2026-15721CRITICALQuery Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human ResourcesEPSS 0.2%CVE-2023-37468MEDIUMStoring unencrypted LDAP passwords in feedbacksystemEPSS 0.2%CVE-2022-28214—During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are beinEPSS 0.2%CVE-2025-32752MEDIUMDell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacker with physical acceEPSS 0.2%CVE-2026-39943MEDIUMDirectus exposes sensitive fields in revision historyEPSS 0.2%CVE-2026-34833HIGHBulwark Webmail: Information Exposure: password returned in /api/auth/sessionEPSS 0.2%CVE-2025-70050MEDIUMAn issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 which allows attackersEPSS 0.2%CVE-2026-6553HIGHTYPO3 CMS Stores Cleartext Password in User Settings ModuleEPSS 0.2%CVE-2018-16498—In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These EPSS 0.2%CVE-2025-46634HIGHCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated aEPSS 0.2%CVE-2024-45718MEDIUMSensitive data disclosure vulnerabilityEPSS 0.2%CVE-2024-53651MEDIUMA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CEPSS 0.2%CVE-2025-2181MEDIUMCheckov by Prisma Cloud: Cleartext Exposure of CredentialsEPSS 0.2%CVE-2026-3277MEDIUMThe OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext iEPSS 0.2%CVE-2025-67638MEDIUMJenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasEPSS 0.2%