Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2021-29500HIGHMissing validation of JWT signatureEPSS 0.6%CVE-2023-28610CRITICALThe update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update imaEPSS 0.6%CVE-2021-3051HIGHCortex XSOAR: Authentication Bypass in SAML AuthenticationEPSS 0.6%CVE-2023-22742MEDIUMlibgit2 fails to verify SSH keys by defaultEPSS 0.6%CVE-2025-13662HIGHImproper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1EPSS 0.6%CVE-2019-10136MEDIUMIt was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired,EPSS 0.6%CVE-2026-10754HIGHPega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.EPSS 0.6%CVE-2023-39969CRITICALuthenticode signature validation bypass vulnerabilityEPSS 0.6%CVE-2023-5747HIGHCommand injection via wave install fileEPSS 0.6%CVE-2025-33074HIGHAzure Functions Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-15265CRITICALTenable Agent Path Traversal Leading to Remote Code ExecutionEPSS 0.6%CVE-2020-22653CRITICALIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.6%CVE-2024-48948MEDIUMThe Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at EPSS 0.6%CVE-2026-27962CRITICALAuthlib JWS JWK Header Injection: Signature Verification BypassEPSS 0.5%CVE-2025-54369CRITICALNode-SAML SAML Authentication BypassEPSS 0.5%CVE-2026-33895HIGHForge has signature forgery in Ed25519 due to missing S > L checkEPSS 0.5%CVE-2026-4115MEDIUMPuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verificationEPSS 0.5%CVE-2022-39237MEDIUMDigital Signature Hash Algorithms Not Validated in sylabs/sifEPSS 0.5%CVE-2024-56161HIGHImproper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicEPSS 0.5%CVE-2023-24025HIGHCRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signaEPSS 0.5%