Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2022-39299HIGHSignature bypass via multiple root elements in Passport-SAMLEPSS 3.4%CVE-2020-24429HIGHAcrobat Reader DC for macOS Signature Verification Bypass Could Lead to Privilege EscalationEPSS 3.0%CVE-2025-31489HIGHMinIO performs incomplete signature validation for unsigned-trailer uploadsEPSS 2.4%CVE-2024-8698HIGHKeycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloakEPSS 2.0%CVE-2018-16151HIGHIn verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation baEPSS 1.9%CVE-2018-16152HIGHIn verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation baEPSS 1.9%CVE-2025-23369HIGHImproper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper ValidationEPSS 1.6%CVE-2019-14859HIGHA flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. WithoutEPSS 1.5%CVE-2024-6800CRITICALAn XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identityEPSS 1.5%CVE-2026-47212MEDIUMSymfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event InjectionEPSS 1.5%CVE-2026-15013CRITICALSAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm ConfusionEPSS 1.5%CVE-2021-41831Timestamp Manipulation with Signature WrappingEPSS 1.5%CVE-2024-0567HIGHGnutls: rejects certificate chain with distributed trustEPSS 1.4%CVE-2020-15705MEDIUMGRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shimEPSS 1.4%CVE-2021-41830Double Certificate AttackEPSS 1.4%CVE-2020-15093HIGHImproper verification of signature threshold in toughEPSS 1.4%CVE-2021-41832Content Manipulation with Certificate Validation AttackEPSS 1.3%CVE-2023-5347CRITICALUnauthenticated Firmware UpgradeEPSS 1.3%CVE-2022-26510CRITICALA firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafteEPSS 1.3%CVE-2021-21239MEDIUMOpen default xmlsec1 key-type preferenceEPSS 1.3%