Weaknesses of type CWE-347

641 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-44714HIGHbitcoinj: ScriptExecution P2PKH/P2WPKH Verification BypassEPSS 0.3%CVE-2025-29915HIGHSuricata af-packet: defrag option can lead to truncated packets affecting visibilityEPSS 0.3%CVE-2026-32597HIGHPyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)EPSS 0.3%CVE-2023-25934MEDIUM DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability toEPSS 0.3%CVE-2026-36721CRITICALA lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authenticatioEPSS 0.3%CVE-2024-7481HIGHImproper signature verification of Printer driver installation in TeamViewer Remote ClientsEPSS 0.3%CVE-2026-45755MEDIUMSymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionEPSS 0.3%CVE-2026-50634MEDIUMApache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entryEPSS 0.3%CVE-2022-31123MEDIUMGrafana plugin signature bypass vulnerabilityEPSS 0.3%CVE-2026-49998HIGHCentrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypassEPSS 0.3%CVE-2026-44104CRITICALControllerAgent does not perform validation of firmwareEPSS 0.3%CVE-2019-1811MEDIUMCisco NX-OS CLI Command Software Image Signature Verification VulnerabilitiesEPSS 0.3%CVE-2026-40941HIGHCacti: Package Import Signature Validation Bypass Allows Self-Signed PackagesEPSS 0.3%CVE-2026-34840HIGHOneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature VerificationEPSS 0.3%CVE-2026-48758MEDIUMsigstore-js: DSSE payloadType type-binding failureEPSS 0.3%CVE-2024-23960MEDIUMAlpine Halo9 Improper Verification of Cryptographic Signature VulnerabilityEPSS 0.3%CVE-2019-1810MEDIUMCisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification VulnerabilityEPSS 0.3%CVE-2026-6966HIGHSignature Threshold Bypass in awslabs/tough Delegated RolesEPSS 0.3%CVE-2026-45795MEDIUMJanssen Project: JWE Request Object Signature Verification Bypass in jans-auth-serverEPSS 0.3%CVE-2024-36277MEDIUMImproper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iEPSS 0.3%