Weaknesses of type CWE-347

642 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2025-43521MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2025-43390MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2024-40592MEDIUMAn improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, verEPSS 0.1%CVE-2026-1237LOWVulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to upEPSS 0.1%CVE-2023-40727HIGHA vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak oEPSS 0.1%CVE-2026-66776MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.1%CVE-2026-41005CRITICALUAA accepts SAML Encrypted Assertions authentication bypassEPSS 0.1%CVE-2026-57122HIGHPraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)EPSS 0.1%CVE-2026-95503MEDIUMKeycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabledEPSS 0.1%CVE-2026-34240HIGHjose vulnerable to untrusted JWK header key acceptance during signature verificationEPSS 0.1%CVE-2026-82645CRITICALAVideo Unauthenticated Stream Credential Disclosure via Forgeable TokenEPSS 0.1%CVE-2025-0824LOWlack of validation for firmware update in Hitachi Virtual StorageEPSS 0.1%CVE-2024-5912MEDIUMCortex XDR Agent: Improper File Signature Verification ChecksEPSS 0.1%CVE-2026-32294HIGHJetKVM insufficient firmware verificationEPSS 0.1%CVE-2026-48523MEDIUMPyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keysEPSS 0.1%CVE-2026-42193CRITICALPlunk: SNS webhook forgeryEPSS 0.1%CVE-2024-23460MEDIUMIncorrect signature validation of packageEPSS 0.1%CVE-2024-47476HIGHDell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthEPSS 0.1%CVE-2026-68745HIGHApache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdPEPSS 0.1%CVE-2026-48021CRITICALepa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vauEPSS 0.1%