Weaknesses of type CWE-312

469 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2026-19391MEDIUMInsights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archivesEPSS 0.2%CVE-2024-12079MEDIUMECOVACS lawnmowers cleartext storage of anti-theft PINEPSS 0.2%CVE-2022-2513HIGHCleartext Credentials Vulnerability on Hitachi Energy’s Multiple IED Connectivity Packages (IED ConnPacks) and PCM600 ProductsEPSS 0.1%CVE-2025-47820LOWFlock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.EPSS 0.1%CVE-2024-55928MEDIUMClear text secrets returned & Remote system secrets in clear textEPSS 0.1%CVE-2026-10786MEDIUMImproper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain clEPSS 0.1%CVE-2025-6224MEDIUMKey leakage in juju/utils certificatesEPSS 0.1%CVE-2026-6796MEDIUMSanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in fileEPSS 0.1%CVE-2026-5224MEDIUMSensitive Data Exposure in Kriptek Crypto's CryptosimEPSS 0.1%CVE-2026-76378MEDIUMInformation Disclosure through Action Parameters in Cisco Secure Malware Analytics app for Splunk SOAREPSS 0.1%CVE-2025-4053MEDIUMUnauthorized creation of master key in Mifare Classic Be-Tech cardsEPSS 0.1%CVE-2025-2189MEDIUMInformation Disclosure Vulnerability in Tinxy Smart DevicesEPSS 0.1%CVE-2026-76379MEDIUMInformation Disclosure through Action Parameters in Cisco Webex app for Splunk SOAREPSS 0.1%CVE-2024-28327HIGHAsus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify routerEPSS 0.1%CVE-2026-33003MEDIUMJenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they EPSS 0.1%CVE-2025-47824LOWFlock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.EPSS 0.1%CVE-2024-40594LOWThe OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible tEPSS 0.1%CVE-2024-50570MEDIUMA Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 tEPSS 0.1%CVE-2026-76377MEDIUMInformation Disclosure through Action Parameters in Azure AD Graph app for Splunk SOAREPSS 0.1%CVE-2026-76405MEDIUMInformation Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) appEPSS 0.1%