Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2021-25636Incorrect trust validation of signature with ambiguous KeyInfo childrenEPSS 1.0%CVE-2021-29451CRITICALMissing validation of JWT signature in `ManyDesigns/Portofino`EPSS 0.9%CVE-2022-24773MEDIUMImproper Verification of Cryptographic Signature in `node-forge`EPSS 0.9%CVE-2022-21134HIGHA firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A spEPSS 0.9%CVE-2020-15091MEDIUMDenial of Service in TenderMintEPSS 0.9%CVE-2024-41138HIGHA library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.281EPSS 0.9%CVE-2020-15216MEDIUMSignature Validation Bypass in goxmldsigEPSS 0.9%CVE-2022-42010MEDIUMAn issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can caEPSS 0.9%CVE-2025-24043HIGHWinDbg Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-39804HIGHA library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's acceEPSS 0.9%CVE-2026-54733CRITICALmoodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpointEPSS 0.9%CVE-2024-21917CRITICALRockwell Automation FactoryTalk® Service Platform Service Token VulnerabilityEPSS 0.9%CVE-2020-14515CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file sigEPSS 0.8%CVE-2024-41159HIGHA library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access priEPSS 0.8%CVE-2024-32962CRITICALXML signature verification bypass due improper verification of signature / signature spoofingEPSS 0.8%CVE-2020-26244MEDIUMCryptographic issues in Python oicEPSS 0.8%CVE-2018-16557HIGHA vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMAEPSS 0.8%CVE-2021-29108HIGHThere is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below.EPSS 0.8%CVE-2021-36226CRITICALWestern Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.EPSS 0.8%CVE-2023-35373MEDIUMMono Authenticode Validation Spoofing VulnerabilityEPSS 0.8%