Weaknesses of type CWE-347

642 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-41431HIGHZen Browser MAR updater ships with signature verification removed — unsigned updates acceptedEPSS 0.2%CVE-2025-4371HIGHA potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical acceEPSS 0.2%CVE-2026-89086CRITICALIn the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proEPSS 0.2%CVE-2026-6328HIGHXQUIC Improper STREAM Frame Validation in Initial/Handshake PacketsEPSS 0.2%CVE-2026-85393HIGHnode-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm PaddingEPSS 0.2%CVE-2026-18092HIGHNet::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtreeEPSS 0.2%CVE-2026-57910CRITICALWatchGuard Agent improper authentication allows unauthenticated remote code executionEPSS 0.2%CVE-2024-7788HIGHSignatures in "repair mode" should not be trustedEPSS 0.2%CVE-2026-46349MEDIUMMastodon: LD-Signature Bypass via JSON-LD Named-Graph RestructuringEPSS 0.2%CVE-2026-68757HIGHPotential improper SAML signature verification in JFrog ArtifactoryEPSS 0.2%CVE-2026-54783HIGHCoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messagesEPSS 0.2%CVE-2025-20181MEDIUMA vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, locEPSS 0.2%CVE-2024-32911HIGHThere is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additioEPSS 0.2%CVE-2026-18152HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.2%CVE-2026-41669HIGHAdmidio: SAML Signature Validation Result Ignored — Forged AuthnRequests and LogoutRequests ProcessedEPSS 0.2%CVE-2026-18568HIGHXML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic checkEPSS 0.2%CVE-2026-48815HIGHsigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforcedEPSS 0.2%CVE-2026-6331LOWHMAC zero-length tag forgery in EVP_DigestVerifyFinalEPSS 0.2%CVE-2023-28806MEDIUMSignature validation error in DLL allows disabling anti-tampering protectionEPSS 0.2%CVE-2024-2307MEDIUMOsbuild-composer: race condition may disable gpg verification for package repositoriesEPSS 0.2%