Weaknesses of type CWE-312

470 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2022-31697MEDIUMThe vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with aEPSS 0.1%CVE-2024-10523MEDIUMInformation Disclosure Vulnerability in TP-Link IoT Smart HubEPSS 0.1%CVE-2025-23291LOWNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized actioEPSS 0.1%CVE-2020-10706MEDIUMA flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This fEPSS 0.1%CVE-2023-32483MEDIUM Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerability. An authenticated malicious user havinEPSS 0.1%CVE-2025-32353HIGHKaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuraEPSS 0.1%CVE-2024-55582MEDIUMOxide before 6 has unencrypted Control Plane datastores.EPSS 0.1%CVE-2022-48310MEDIUMAn information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versionEPSS 0.1%CVE-2023-39210MEDIUMCleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an informaEPSS 0.1%CVE-2021-35526MEDIUMStorage of Sensitive Information Vulnerability in Hitachi ABB Power Grids System Data Manager – SDM600 ProductEPSS 0.1%CVE-2022-34910MEDIUMAn issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. HoweEPSS 0.1%CVE-2025-53758MEDIUMDefault Credential Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.1%CVE-2024-25661HIGHIn Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop applicatEPSS 0.1%CVE-2026-6332MEDIUMClear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVACEPSS 0.1%CVE-2022-42284MEDIUMNVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.EPSS 0.1%CVE-2026-9274MEDIUMInformation Exposure Vulnerability in CP-Plus Wi-Fi CameraEPSS 0.1%CVE-2026-4346MEDIUMCleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Link's TL-WR850NEPSS 0.1%CVE-2025-48463LOWUnencrypted HTTP CommunicationEPSS 0.1%CVE-2023-32447MEDIUM Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local acEPSS 0.1%CVE-2023-32455MEDIUM Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious uEPSS 0.1%