Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2024-31486MEDIUMA vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without suEPSS 0.5%CVE-2022-39364MEDIUMException logging in Sharepoint app reveals clear-text connection detailsEPSS 0.5%CVE-2021-35036MEDIUMA cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated atEPSS 0.5%CVE-2022-24188HIGHThe /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the pictuEPSS 0.5%CVE-2024-24375HIGHSQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.EPSS 0.5%CVE-2023-45151MEDIUMOAuth2 client_secret stored in plain text in the Nextcloud databaseEPSS 0.5%CVE-2026-15065CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2023-23944LOWNexcloud Mail app temporarily stores cleartext password in databaseEPSS 0.5%CVE-2022-41933MEDIUMPlaintext storage of password in org.xwiki.platform:xwiki-platform-security-authentication-defaultEPSS 0.5%CVE-2024-36497CRITICALUnhashed Storage of PasswordEPSS 0.5%CVE-2021-29481MEDIUMClient side sessions should not allow unencrypted storageEPSS 0.5%CVE-2023-22584HIGHCleartext credentials in Danfoss AK-EM100EPSS 0.5%CVE-2022-48073HIGHPhicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.EPSS 0.5%CVE-2024-28387HIGHAn issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.EPSS 0.4%CVE-2020-8276—The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the useEPSS 0.4%CVE-2024-41716HIGHCleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker EPSS 0.4%CVE-2022-48071HIGHPhicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.EPSS 0.4%CVE-2023-0690MEDIUMBoundary Workers Store Rotated Credentials in Plaintext Even When a Key Management Service ConfiguredEPSS 0.4%CVE-2024-58277HIGHR Radio Network FM Transmitter 1.07 System Settings DisclosureEPSS 0.4%CVE-2023-28713HIGHPlaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database isEPSS 0.4%