Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2022-2720MEDIUMIn affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value maskinEPSS 0.5%CVE-2023-25819MEDIUMDiscourse tags with no visibility are leaking into og:article:tagEPSS 0.5%CVE-2024-49025MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-4767MEDIUMIf the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. ThisEPSS 0.5%CVE-2025-43500HIGHA privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1,EPSS 0.5%CVE-2025-43496HIGHThe issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS SeqEPSS 0.5%CVE-2025-53765MEDIUMAzure Stack Hub Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-0102LOWMicrosoft Edge (Chromium-based) Defense in Depth VulnerabilityEPSS 0.5%CVE-2025-13008HIGHSession Token Disclosure in M-Files WebEPSS 0.5%CVE-2026-26237MEDIUMQuMagieEPSS 0.5%CVE-2026-73008MEDIUMWindows Biometric Service Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-69351MEDIUMWindows Universal Plug and Play (UPnP) Device Host Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-33271HIGHAn issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component.EPSS 0.5%CVE-2024-53258HIGHdownload_all_submissions allows student to download another student's submissions in AutolabEPSS 0.5%CVE-2024-11712MEDIUMWP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume DownloadEPSS 0.5%CVE-2023-34085LOWUser Attribute Disclosure via DynamoDB Data StoresEPSS 0.5%CVE-2026-92565MEDIUMRallly before 4.15.0 Information Disclosure via polls.getEPSS 0.5%CVE-2025-62644MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal informatioEPSS 0.5%CVE-2024-38103MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-28387HIGHAn issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.EPSS 0.4%