Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2023-45721MEDIUMHCL Domino Volt and Domino Leap are affected by a disclosure of private personal information vulnerabilityEPSS 0.3%CVE-2024-42325LOWExcessive information returned by user.getEPSS 0.3%CVE-2025-14317HIGHUser Enumeration in Crazy Bubble Tea mobile applicationEPSS 0.3%CVE-2025-43259MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, mEPSS 0.3%CVE-2025-3035MEDIUMTab title disclosure across pages when using AI chatbotEPSS 0.3%CVE-2026-8990MEDIUMAuthentication Bypass in KidsviewEPSS 0.3%CVE-2025-11959HIGHImproper Access Control in Premierturk's Excavation Management Information SystemEPSS 0.3%CVE-2025-3950LOWExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.3%CVE-2024-44113MEDIUMInformation Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)EPSS 0.3%CVE-2024-41729MEDIUMInformation Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)EPSS 0.3%CVE-2025-15623CRITICALSparx Pro Cloud Server reveals sensitive information to an unauthenticated userEPSS 0.3%CVE-2024-49386MEDIUMSensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0EPSS 0.2%CVE-2025-20615MEDIUMQardio Heart Health IOS Mobile Application Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.2%CVE-2024-37533LOWIBM InfoSphere Information Server information disclosureEPSS 0.2%CVE-2025-43357MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOEPSS 0.2%CVE-2023-25632—The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.EPSS 0.2%CVE-2025-10450HIGHExposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.EPSS 0.2%CVE-2025-43301LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma EPSS 0.2%CVE-2025-13477HIGHOTP Bypass in Digital Operation Services' WifiBuradaEPSS 0.2%CVE-2025-24355HIGHUpdatecli may expose Maven credentials in console outputEPSS 0.2%