Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2017-3214—The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.EPSS 0.6%CVE-2015-8314HIGHThe Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persisEPSS 0.6%CVE-2021-23878HIGHClear text storage of sensitive Information in ENSEPSS 0.6%CVE-2023-24450MEDIUMJenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be EPSS 0.6%CVE-2019-6549—An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or SoftwareEPSS 0.6%CVE-2019-18238—In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive informatioEPSS 0.6%CVE-2023-4392LOWControl iD Gerencia Web Cookie cleartext storageEPSS 0.6%CVE-2023-27706HIGHBitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other loEPSS 0.6%CVE-2025-34270MEDIUMNagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not ObfuscatedEPSS 0.6%CVE-2020-15085MEDIUMClient caching login operation with plaintext password in Saleor StorefrontEPSS 0.6%CVE-2020-15784—A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuEPSS 0.6%CVE-2026-8596HIGHCleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve pathEPSS 0.6%CVE-2024-4235LOWNetgear DG834Gv5 Web Management Interface cleartext storageEPSS 0.6%CVE-2022-43757CRITICALRancher: Exposure of sensitive fieldsEPSS 0.6%CVE-2023-24586LOWCleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authentEPSS 0.5%CVE-2024-4540HIGHKeycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookieEPSS 0.5%CVE-2023-5384HIGHInfinispan: credentials returned from configuration as clear textEPSS 0.5%CVE-2021-20995MEDIUMWAGO: Managed Switches: Storage of user credentials in a cookieEPSS 0.5%CVE-2022-37785HIGHAn issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.EPSS 0.5%CVE-2025-34206CRITICALVasion Print (formerly PrinterLogic) Insecure Shared Storage PermissionsEPSS 0.5%