Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2023-28713HIGHPlaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database isEPSS 0.4%CVE-2022-2813MEDIUMSourceCodester Guest Management System cleartext storageEPSS 0.4%CVE-2022-2805MEDIUMA flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allowsEPSS 0.4%CVE-2024-32474HIGHSentry's superuser cleartext password leaked in logsEPSS 0.4%CVE-2023-31408MEDIUMCleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 112252EPSS 0.4%CVE-2022-34339MEDIUM"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-FEPSS 0.4%CVE-2023-44159MEDIUMSensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber ProteEPSS 0.4%CVE-2020-36887HIGHSpinetiX Fusion Digital Signage 3.4.8 Unauthenticated Database Backup DisclosureEPSS 0.4%CVE-2023-22949MEDIUMAn issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requeEPSS 0.4%CVE-2021-42066—SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypteEPSS 0.4%CVE-2023-50957HIGHIBM Storage Defender - Resiliency Service privilege escalationEPSS 0.4%CVE-2022-38112HIGHSensitive Information Disclosure VulnerabilityEPSS 0.4%CVE-2020-6980—Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versionsEPSS 0.4%CVE-2023-48700MEDIUMClear Text Credentials Exposed via Onboarding TaskEPSS 0.4%CVE-2023-29480HIGHRibose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.EPSS 0.4%CVE-2021-22929—An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps oEPSS 0.4%CVE-2023-2809HIGHUse of Cleartext credentials in Sage 200 SpainEPSS 0.4%CVE-2023-30528MEDIUMJenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potentEPSS 0.4%CVE-2023-30531MEDIUMJenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasinEPSS 0.4%CVE-2024-22084HIGHAn issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed throughEPSS 0.4%