Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2025-13477HIGHOTP Bypass in Digital Operation Services' WifiBuradaEPSS 0.2%CVE-2026-24321MEDIUMInformation Disclosure vulnerability in SAP Commerce CloudEPSS 0.2%CVE-2025-43452MEDIUMThis issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggesEPSS 0.2%CVE-2025-43279MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be ablEPSS 0.2%CVE-2025-53374LOWDokploy Improperly Discloses User Information via user.one EndpointEPSS 0.2%CVE-2025-43310MEDIUMA configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe EPSS 0.2%CVE-2020-25900MEDIUMHelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, EPSS 0.2%CVE-2025-43217MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Privacy Indicators for mEPSS 0.2%CVE-2026-28836MEDIUMA correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be EPSS 0.2%CVE-2026-28963MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical acEPSS 0.2%CVE-2025-27080MEDIUMAuthenticated Sensitive Information Disclosure exposes Credentials in AOS-CX Command Line InterfaceEPSS 0.2%CVE-2026-28950MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7EPSS 0.2%CVE-2026-54565MEDIUMrhwp browser extension performs SSRF / private-network requests and leaks HWP preview data to untrusted pagesEPSS 0.2%CVE-2025-43409MEDIUMA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An apEPSS 0.2%CVE-2024-41780MEDIUMIBM Jazz Foundation information disclosureEPSS 0.2%CVE-2025-1939LOWTapjacking in Android Custom Tabs using transition animationsEPSS 0.2%CVE-2025-43439MEDIUMA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, visEPSS 0.2%CVE-2023-42830LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and EPSS 0.2%CVE-2025-53950MEDIUMAn Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin fEPSS 0.2%CVE-2025-43389MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1EPSS 0.2%