Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2026-53497MEDIUMCrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)EPSS 0.4%CVE-2026-3911LOWOrg.keycloak.services.resources.admin.userresource: keycloak: information disclosure of disabled user attributes via administrative endpointEPSS 0.4%CVE-2026-76855HIGHNetcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit EndpointsEPSS 0.4%CVE-2026-54264HIGHAngular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service WorkerEPSS 0.4%CVE-2025-0969MEDIUMBrizy – Page Builder <= 2.7.16 - Authenticated (Contributor+) Sensitive Information Exposure via get_users FunctionEPSS 0.4%CVE-2026-61588MEDIUMdjust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the clientEPSS 0.4%CVE-2026-7382MEDIUMInformation Disclosure in MeWare Software's PDKSEPSS 0.4%CVE-2026-49344HIGHMercator has a Personal Identifiable Information Leak from Query Executor featureEPSS 0.4%CVE-2024-11206HIGHUnauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.EPSS 0.4%CVE-2024-13217MEDIUMJeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-CanvasEPSS 0.4%CVE-2024-23211LOWA privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, EPSS 0.4%CVE-2024-36677HIGHIn the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to eEPSS 0.4%CVE-2024-36682HIGHIn the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SEPSS 0.4%CVE-2026-28938HIGHA privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint tEPSS 0.4%CVE-2022-0852—There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could EPSS 0.4%CVE-2025-41685MEDIUMSMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated userEPSS 0.4%CVE-2026-55496MEDIUMCloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicateEPSS 0.4%CVE-2024-13228MEDIUMQubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_contentEPSS 0.4%CVE-2026-41182MEDIUMLangSmith SDK: Streaming token events bypass output redactionEPSS 0.4%CVE-2025-66510MEDIUMNextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact listEPSS 0.4%