Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2025-66567CRITICALruby-saml has a SAML authentication bypass due to namespace handling (parser differential)EPSS 0.4%CVE-2023-34205CRITICALIn Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, EPSS 0.4%CVE-2025-27773HIGHSimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect bindingEPSS 0.4%CVE-2023-2030LOWImproper Verification of Cryptographic Signature in GitLabEPSS 0.4%CVE-2026-50721HIGHIKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payloadEPSS 0.4%CVE-2023-44077CRITICALStudio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.EPSS 0.4%CVE-2026-54773MEDIUMCoreWCF: WS-Security signature substitution via document-wide Signature lookupEPSS 0.4%CVE-2023-47122MEDIUMGitsign's Rekor public keys fetched from upstream API instead of local TUF client.EPSS 0.4%CVE-2025-54419CRITICALNode-SAML Contains SAML Signature Verification VulnerabilityEPSS 0.4%CVE-2026-9027MEDIUMCorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST EndpointEPSS 0.4%CVE-2025-20178MEDIUMCisco Secure Network Analytics Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-24807MEDIUMBuffer Overflow Vulnerability in liuyueyi/quick-mediaEPSS 0.4%CVE-2026-3564CRITICALScreenConnect Instance Level Cryptographic Material ExposureEPSS 0.4%CVE-2023-53951CRITICALEver Gauzy v0.281.9 JWT Authentication Weakness via HMAC SecretEPSS 0.4%CVE-2023-25574CRITICALJupyterHub's LTI13Authenticator: JWT signature not validatedEPSS 0.4%CVE-2023-41037MEDIUMCleartext Signed Message Signature Spoofing in openpgpjsEPSS 0.4%CVE-2023-33959HIGHVerification bypass can cause users into verifying the wrong artifactEPSS 0.4%CVE-2022-3864MEDIUM A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After rEPSS 0.4%CVE-2024-37532HIGHIBM WebSphere Application Server identity spoofingEPSS 0.4%CVE-2022-39200HIGHSignature checks not applied to some retrieved missing eventsEPSS 0.4%