Weaknesses of type CWE-347

640 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-33894HIGHForge has signature forgery in RSA-PKCS due to ASN.1 extra fieldEPSS 0.5%CVE-2023-34435HIGHA firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted networEPSS 0.5%CVE-2024-34358MEDIUMTYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageControllerEPSS 0.5%CVE-2016-20021CRITICALIn Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file bEPSS 0.5%CVE-2026-56207CRITICALApache Impala: SAML authentication bypass via forged bearer tokenEPSS 0.5%CVE-2025-47949CRITICALsamlify SAML Signature Wrapping attackEPSS 0.5%CVE-2020-12046—Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an atEPSS 0.5%CVE-2025-68113MEDIUMALTCHA Proof-of-Work Vulnerable to Challenge Splicing and ReplayEPSS 0.5%CVE-2023-23772HIGHMotorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature vEPSS 0.5%CVE-2023-23773HIGHMotorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation foEPSS 0.5%CVE-2026-1529HIGHOrg.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validationEPSS 0.5%CVE-2024-8531HIGHCWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when anEPSS 0.5%CVE-2023-23928MEDIUMreason-jose ignores signature checksEPSS 0.5%CVE-2023-28228MEDIUMWindows Spoofing VulnerabilityEPSS 0.5%CVE-2026-62918HIGHMicrosoft Teams Spoofing VulnerabilityEPSS 0.5%CVE-2026-59243CRITICALApache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)EPSS 0.4%CVE-2025-64787LOWAcrobat Reader | Improper Verification of Cryptographic Signature (CWE-347)EPSS 0.4%CVE-2023-3347MEDIUMSamba: smb2 packet signing is not enforced when "server signing = required" is setEPSS 0.4%CVE-2025-64786LOWAcrobat Reader | Improper Verification of Cryptographic Signature (CWE-347)EPSS 0.4%CVE-2025-59334CRITICALLinkr allows manifest tampering leading to arbitrary file injectionEPSS 0.4%