Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-62873CRITICALMicrosoft 365 Admin Center Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2021-20319An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the iEPSS 0.5%CVE-2023-42806MEDIUMSnapshot signature not including HeadID will allow replay attacksEPSS 0.5%CVE-2023-1204MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 befoEPSS 0.5%CVE-2020-12042Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. AEPSS 0.5%CVE-2023-46234MEDIUMbrowserify-sign vulnerable via an upper bound check issue in `dsaVerify` that leads to a signature forgery attackEPSS 0.5%CVE-2024-13172HIGHImproper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows EPSS 0.5%CVE-2022-24759HIGHFailure to validate signature during handshake in @chainsafe/libp2p-noiseEPSS 0.5%CVE-2026-56451CRITICALA vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm speciEPSS 0.5%CVE-2024-48949CRITICALThe verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) ||EPSS 0.5%CVE-2023-50714MEDIUMThe Oauth2 PKCE implementation is vulnerableEPSS 0.5%CVE-2023-40178MEDIUM@node-saml/node-saml's validatePostRequestAsync does not include checkTimestampsValidityErrorEPSS 0.5%CVE-2026-50010HIGHNetty's wrapping plain trust manager silently disables hostname verificationEPSS 0.5%CVE-2020-10759A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, aEPSS 0.5%CVE-2018-25099CRITICALIn the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.EPSS 0.5%CVE-2023-20266MEDIUMA vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager SessioEPSS 0.5%CVE-2026-23687HIGHXML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP PlatformEPSS 0.5%CVE-2025-55229MEDIUMWindows Certificate Spoofing VulnerabilityEPSS 0.5%CVE-2026-33117CRITICALAzure SDK for Java Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2020-25166HIGHB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 0.5%