Weaknesses of type CWE-347

642 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-9793MEDIUMKeycloak: keycloak: security policy bypass in jwe-encrypted request object processingEPSS 0.2%CVE-2026-3706MEDIUMmkj Dropbear S Range Check curve25519.c unpackneg signature verificationEPSS 0.2%CVE-2026-22817HIGHJWT Algorithm Confusion via Unsafe Default (HS256) in Hono JWT Middleware Allows Token Forgery and Auth BypassEPSS 0.2%CVE-2026-13743LOWImproper verification of cryptographic signature in CubeSpace CW0057 Reaction WheelEPSS 0.2%CVE-2022-24115—Local privilege escalation due to unrestricted loading of unsigned librariesEPSS 0.2%CVE-2026-18569LOWKeycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokensEPSS 0.2%CVE-2026-47191LOWkas checks out SHA-like git branches as valid commitsEPSS 0.2%CVE-2026-86080MEDIUMn8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-OpenEPSS 0.2%CVE-2026-2746MEDIUMMissing PGP Signature TagEPSS 0.2%CVE-2026-18500HIGH@fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request keyEPSS 0.2%CVE-2025-9210HIGHMissing JSON Web Token signature validation in Otalio Ship Property Management SystemEPSS 0.2%CVE-2026-32883MEDIUMBotan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation BypassEPSS 0.2%CVE-2025-43185MEDIUMA downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An app may be able to EPSS 0.2%CVE-2026-55165MEDIUMLemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosureEPSS 0.2%CVE-2024-24694MEDIUMZoom Desktop Client for Windows - Improper Privilege ManagementEPSS 0.2%CVE-2021-34709MEDIUMCisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Image Verification VulnerabilitiesEPSS 0.2%CVE-2022-31807MEDIUMA vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected devices do not properEPSS 0.2%CVE-2025-59327HIGHIn CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is presEPSS 0.1%CVE-2025-68925MEDIUMJervis has a JWT Algorithm Confusion VulnerabilityEPSS 0.1%CVE-2022-36056MEDIUM Vulnerabilities with blob verification in sigstore cosignEPSS 0.1%