Weaknesses of type CWE-312

470 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2023-32455MEDIUM Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious uEPSS 0.1%CVE-2025-34428HIGHMailEnable < 10.54 Cleartext Credential Storage in AUTH.SAVEPSS 0.1%CVE-2023-32448MEDIUM PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the instEPSS 0.1%CVE-2025-0123MEDIUMPAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet CapturesEPSS 0.1%CVE-2024-31415MEDIUMThe Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network manageEPSS 0.1%CVE-2024-47056MEDIUMMautic does not shield .env files from web trafficEPSS 0.1%CVE-2022-4312MEDIUM A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized uEPSS 0.1%CVE-2023-39440MEDIUMInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence PlatformEPSS 0.1%CVE-2025-2182MEDIUMPAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK)EPSS 0.1%CVE-2025-34427HIGHMailEnable < 10.54 Cleartext Credential Storage in AUTH.TABEPSS 0.1%CVE-2023-46294LOWAn issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwEPSS 0.1%CVE-2024-25023MEDIUMIBM QRadar Suite Software information disclosureEPSS 0.1%CVE-2025-27460HIGHCVE-2025-27460EPSS 0.1%CVE-2024-28807MEDIUMAn issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop managementEPSS 0.1%CVE-2024-29954MEDIUMpassword management API prints sensitive information in log filesEPSS 0.1%CVE-2024-23942HIGHMB connect line: Configuration File on the client workstation is not encryptedEPSS 0.1%CVE-2024-8070HIGHCWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binaryEPSS 0.1%CVE-2024-29952MEDIUMClear text storage of sensistive information by manipulating command variables EPSS 0.1%CVE-2026-21080MEDIUMCleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.EPSS 0.1%CVE-2024-51993LOWPassword is stored in clear in the database in Combodo iTopEPSS 0.1%