Weaknesses of type CWE-347

642 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-74901CRITICALopenssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR FallbackEPSS 0.2%CVE-2026-2968MEDIUMCesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verificationEPSS 0.2%CVE-2017-12333—A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a EPSS 0.2%CVE-2026-58085HIGHMissing MAC validation in wg(4) packet decryptionEPSS 0.2%CVE-2026-49454CRITICALRelyra SAML SignatureValue not cryptographically verified -> authentication bypassEPSS 0.2%CVE-2026-9832MEDIUMPayment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook EndpointEPSS 0.2%CVE-2023-54355HIGHPocketMine-MP 5.2.0 Server Crash via Incorrect EC CurveEPSS 0.2%CVE-2026-4600CRITICALVersions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameEPSS 0.2%CVE-2026-86304CRITICALMojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchorEPSS 0.2%CVE-2026-76234HIGHlibcrux before 0.0.6 Cryptographic Implementation Bug FixesEPSS 0.2%CVE-2025-52550HIGHFirmware upgrade packages are unsignedEPSS 0.2%CVE-2021-1453MEDIUMCisco IOS XE Software for the Catalyst 9000 Family Arbitrary Code Execution VulnerabilityEPSS 0.2%CVE-2020-10608—In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI SyEPSS 0.2%CVE-2026-85394CRITICALpython-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC SecretEPSS 0.2%CVE-2026-42602HIGHazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replayEPSS 0.2%CVE-2026-46423CRITICALRocket.Chat: SAML signature validation skipped when IdP certificate field is emptyEPSS 0.2%CVE-2026-65616HIGHPotential privilege escalation to JFrog administrator privilegesEPSS 0.2%CVE-2026-52767HIGHYesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`EPSS 0.2%CVE-2025-41767HIGHSignature bypass on update uploadEPSS 0.2%CVE-2023-23940MEDIUMOpenZeppelin Contracts for Cairo is vulnerable to signature validation bypassEPSS 0.2%