Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2024-42004HIGHA library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library canEPSS 0.8%CVE-2020-15240HIGHRegression in JWT Signature ValidationEPSS 0.8%CVE-2024-41145HIGHA library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. AEPSS 0.8%CVE-2026-3338HIGHPKCS7_verify Signature Validation Bypass in AWS-LCEPSS 0.8%CVE-2022-24771HIGHImproper Verification of Cryptographic Signature in node-forgeEPSS 0.8%CVE-2026-5588MEDIUMPKIX draft CompositeVerifier accepts empty signature sequence as valid.EPSS 0.8%CVE-2024-22461HIGHDell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentiaEPSS 0.8%CVE-2021-29455HIGHMissing validation of JWT signature in `grassrootza/grassroot-platform`EPSS 0.8%CVE-2025-2233HIGHSamsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass VulnerabilityEPSS 0.8%CVE-2024-42220HIGHA library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access pEPSS 0.7%CVE-2024-41165HIGHA library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privilegeEPSS 0.7%CVE-2024-43106HIGHA library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileEPSS 0.7%CVE-2017-15090An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signaturEPSS 0.7%CVE-2016-7064A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakageEPSS 0.7%CVE-2022-23610CRITICALImproper Verification of Cryptographic Signature in wire-serverEPSS 0.7%CVE-2026-12263HIGHAuthentication BypassEPSS 0.7%CVE-2026-9779HIGHATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution VulnerabilityEPSS 0.7%CVE-2021-3421A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seeminglyEPSS 0.7%CVE-2023-34058HIGHVMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges httpsEPSS 0.7%CVE-2023-28226MEDIUMWindows Enroll Engine Security Feature Bypass VulnerabilityEPSS 0.7%