Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2026-42151HIGHPrometheus Azure AD remote write OAuth client secret exposed via config APIEPSS 0.4%CVE-2023-6874HIGHZigbee Unauthenticated DoS via NWK Sequence number manipulationEPSS 0.4%CVE-2022-20660MEDIUMCisco IP Phones Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-36790HIGHNetgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.EPSS 0.3%CVE-2024-52525LOWNextcloud Server User password is available in memory of the PHP processEPSS 0.3%CVE-2025-34200HIGHVasion Print (formerly PrinterLogic) Network Account Password Stored in CleartextEPSS 0.3%CVE-2024-7783MEDIUMImproper Storage of Sensitive Information in Bearer Token in mintplex-labs/anything-llmEPSS 0.3%CVE-2024-46340CRITICALTL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plainteEPSS 0.3%CVE-2025-26495HIGHSensitive Data Exposure in Tableau ServerEPSS 0.3%CVE-2024-8459HIGHPLANET Technology switch devices - Cleartext storage of SNMPv3 users' passwordsEPSS 0.3%CVE-2023-27370MEDIUMNETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure VulnerabilityEPSS 0.3%CVE-2025-27623MEDIUMJenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via RESTEPSS 0.3%CVE-2023-25596MEDIUMAuthenticated Sensitive Information Disclosure in ClearPass Policy ManagerEPSS 0.3%CVE-2024-43429MEDIUMMoodle: user information visibility control issues in gradebook reportsEPSS 0.3%CVE-2025-23215CRITICALPMD Designer's release key passphrase (GPG) available on Maven Central in cleartextEPSS 0.3%CVE-2026-33026CRITICALnginx-ui Backup Restore Allows Tampering with Encrypted BackupsEPSS 0.3%CVE-2023-30530MEDIUMJenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on thEPSS 0.3%CVE-2023-30527MEDIUMJenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins contrEPSS 0.3%CVE-2022-21818MEDIUMNVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user on a network after siEPSS 0.3%CVE-2023-28345MEDIUMAn issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console pasEPSS 0.3%