Weaknesses of type CWE-347

644 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-82876CRITICALPhison PS3111-S11 Controller Firmware Signature Verification BypassEPSS 0.1%CVE-2026-92718HIGHNuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only CacheEPSS 0.1%CVE-2023-32449HIGH Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a hiEPSS 0.1%CVE-2023-23431HIGH Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2024-27247MEDIUMZoom Desktop Client for macOS - Improper Privilege ManagementEPSS 0.1%CVE-2026-81717CRITICALopenssl_encrypt before 1.4.9 Integrity Bypass via Added FilesEPSS 0.1%CVE-2025-43468MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2025-2866LOWPDF signature forgery with adbe.pkcs7.sha1 SubFilterEPSS 0.1%CVE-2025-52648MEDIUMHCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverifieEPSS 0.1%CVE-2025-32060MEDIUMAbsence of Kernel Module Signature Verification on Linux System of Infotainment ECUEPSS 0.1%CVE-2024-1149HIGHImproper validation of update packagesEPSS 0.1%CVE-2025-43522LOWA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2024-1150HIGHImproper validation of update packagesEPSS 0.1%CVE-2022-41669HIGHA CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with loEPSS 0.1%CVE-2026-2625MEDIUMRust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verificationEPSS 0.1%CVE-2023-23436HIGH Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2023-23433MEDIUM Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2025-68972MEDIUMIn GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that placesEPSS 0.1%CVE-2023-23432HIGH Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2025-43903MEDIUMNSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signatEPSS 0.1%