Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2022-39300HIGHSignature bypass via multiple root elements in node-SAMLEPSS 0.7%CVE-2021-3406A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust EPSS 0.7%CVE-2021-32685CRITICALImproper Verification of Cryptographic Signature in tenvoyEPSS 0.7%CVE-2021-22708A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to EPSS 0.7%CVE-2022-35929HIGHFalse positive signature verification in cosignEPSS 0.7%CVE-2022-46176MEDIUMCargo did not verify SSH host keysEPSS 0.6%CVE-2025-47934HIGHOpenPGP.js's message signature verification can be spoofedEPSS 0.6%CVE-2022-35930HIGHAbility to bypass attestation verification in sigstore PolicyControllerEPSS 0.6%CVE-2022-23655MEDIUMMissing server signature validation in OctoberCMSEPSS 0.6%CVE-2021-32977HIGHAVEVA System Platform Improper Verification of Cryptographic SignatureEPSS 0.6%CVE-2020-24439LOWAcrobat Reader DC for macOS Signature Validation BypassEPSS 0.6%CVE-2018-10470Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag andEPSS 0.6%CVE-2024-47943CRITICALImproper signature verification of firmware upgrade filesEPSS 0.6%CVE-2024-21669CRITICALHyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VCEPSS 0.6%CVE-2022-41340HIGHThe secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.EPSS 0.6%CVE-2024-42461MEDIUMIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.EPSS 0.6%CVE-2024-13990CRITICALMicroWorld eScan AV Insecure Update Mechanism Allows Man-in-the-Middle Replacement of UpdatesEPSS 0.6%CVE-2026-57098HIGHMicrosoft Remote Desktop App for Windows Information Disclosure VulnerabilityEPSS 0.6%CVE-2020-3308MEDIUMCisco Firepower Threat Defense Software Signature Verification Bypass VulnerabilityEPSS 0.6%CVE-2025-9485CRITICALOAuth Single Sign On – SSO (OAuth Client) <= 6.26.12 - Authentication Bypass via get_resource_owner_from_id_token()EPSS 0.6%