Weaknesses of type CWE-347

642 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2020-14365—A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packagEPSS 0.2%CVE-2017-12331—A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a EPSS 0.2%CVE-2025-66568CRITICALruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validationEPSS 0.2%CVE-2023-33185MEDIUMIncorrect signature verification in django-sesEPSS 0.2%CVE-2021-1376MEDIUMCisco IOS XE Software Fast Reload VulnerabilitiesEPSS 0.2%CVE-2021-1375MEDIUMCisco IOS XE Software Fast Reload VulnerabilitiesEPSS 0.2%CVE-2026-44748CRITICALXML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP PlatformEPSS 0.2%CVE-2026-42501HIGHMalicious module proxy can bypass checksum database in cmd/goEPSS 0.2%CVE-2026-0234HIGHCortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integrationEPSS 0.2%CVE-2023-42811MEDIUMAEADs/aes-gcm: Plaintext exposed in decrypt_in_place_detached even on tag verification failureEPSS 0.2%CVE-2026-93657HIGHhickory-resolver before 0.26.2 DNSSEC Validation BypassEPSS 0.2%CVE-2026-80469HIGHCVE-2026-80469EPSS 0.2%CVE-2024-49365HIGHtiny-secp256k1 allows for verify() bypass when running in bundled environmentEPSS 0.2%CVE-2026-54248MEDIUMDoco-CD has an OCI Trust Policy Bypass via Artifact-Contained ConfigurationEPSS 0.2%CVE-2026-25922HIGHauthentik has a Signature Verification Bypass via SAML Assertion WrappingEPSS 0.2%CVE-2026-68759HIGHIntegration credential holders may impersonate users in JFrog AccessEPSS 0.2%CVE-2025-40758HIGHA vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendix 10.21 compatible) EPSS 0.2%CVE-2026-54330HIGHCeph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalationEPSS 0.2%CVE-2026-20965HIGHWindows Admin Center Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-74901CRITICALopenssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR FallbackEPSS 0.2%