Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-28802HIGHAuthlib: Setting `alg: none` and a blank signature appears to bypass signature verificationEPSS 0.4%CVE-2026-54782CRITICALCoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validationEPSS 0.4%CVE-2022-23334CRITICALThe Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackersEPSS 0.4%CVE-2024-7479HIGHImproper signature verification of VPN driver installation in TeamViewer Remote ClientsEPSS 0.4%CVE-2025-12295HIGHD-Link DAP-2695 Firmware Update sub_40C6B8 signature verificationEPSS 0.4%CVE-2021-1461MEDIUMCisco SD-WAN Software Signature Verification Bypass VulnerabilityEPSS 0.4%CVE-2025-27670CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OEPSS 0.4%CVE-2002-1796HIGHChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, EPSS 0.4%CVE-2024-21383LOWMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.4%CVE-2025-32977CRITICALQuest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 EPSS 0.4%CVE-2023-49646MEDIUMImproper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via networEPSS 0.4%CVE-2024-47832CRITICALXML Signature Bypass via differential XML parsing in ssoreadyEPSS 0.4%CVE-2023-49079CRITICALMisskey's missing signature validation allows arbitrary users to impersonate any remote user.EPSS 0.4%CVE-2022-47549MEDIUMAn unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allowEPSS 0.4%CVE-2021-31847HIGHImproper privilege management in repair process of MA for WindowsEPSS 0.4%CVE-2025-54982CRITICALSAML 2.0 Public Key Validation IssueEPSS 0.4%CVE-2026-48526HIGHPyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowedEPSS 0.4%CVE-2026-19505CRITICALRDK-B WebUI improper cryptographic signature verification vulnerabilityEPSS 0.4%CVE-2024-54150HIGHAlgorithm Confusion Vulnerability in cjwtEPSS 0.4%CVE-2023-28801CRITICALImproper SAML signature verificationEPSS 0.4%