Weaknesses of type CWE-312

470 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2025-53755MEDIUMCleartext Storage Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.1%CVE-2026-66016MEDIUMRendered Artifactory Helm manifests may contain generated TLS private keysEPSS 0.1%CVE-2026-59327MEDIUMCleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch ConfigurationsEPSS 0.1%CVE-2025-54342LOWA vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive IEPSS 0.1%CVE-2026-24311MEDIUMInsecure Storage Protection vulnerability in SAP Customer Checkout 2.0EPSS 0.1%CVE-2025-63729CRITICALAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA CertifEPSS 0.1%CVE-2025-54464HIGHCleartext Storage Vulnerability in ZKTeco WL20EPSS 0.1%CVE-2026-73834MEDIUMMust-gather: must-gather: embedded secret data in acm wrapper crs collected without redactionEPSS 0.1%CVE-2026-28758MEDIUMBIG-IP iControl REST vulnerabilityEPSS 0.1%CVE-2026-42408MEDIUMBIG-IP DNS tmsh vulnerabilityEPSS 0.1%CVE-2025-55717LOWA cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.EPSS 0.1%CVE-2026-18591LOWMeesho Online Shopping App com.meesho.supply cleartext storageEPSS 0.1%CVE-2025-4737MEDIUMInsufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive informatiEPSS 0.1%CVE-2026-55997HIGHLong-lived Rancher registration token exposed in plaintextEPSS 0.1%CVE-2026-34490MEDIUMXAAP Android Data Stored in Unencrypted DatabaseEPSS 0.1%CVE-2026-41520HIGHCillium exposes sensitive information included in the cilium-bugtool debug archiveEPSS 0.1%CVE-2026-16802MEDIUMCleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local EPSS 0.1%CVE-2025-2909MEDIUMLack of encryption vulnerability in DuoxMeEPSS 0.1%CVE-2026-4130HIGHStorage of Sensitive Information in Cleartext in NI SystemLinkEPSS 0.1%CVE-2026-80058MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage EPSS 0.1%