Weaknesses of type CWE-497

404 results

Divulgação de Informações Sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, dados pessoais) através de canais inseguros ou em contextos onde não deveria — logs, mensagens de erro, cache, memória ou tráfego de rede desencriptado. O risco é um atacante interceptar ou acessar esses dados e comprometer contas, sistemas ou privacidade.

Example

Uma API retorna a senha do usuário em texto plano dentro de um JSON de resposta de erro; um servidor expõe tokens de autenticação em arquivos de log acessíveis publicamente; uma página web carrega chaves de API dentro de variáveis JavaScript visíveis no código-fonte.

How to mitigate

Nunca exponha dados sensíveis em logs, mensagens de erro visíveis ao usuário ou código cliente. Criptografe dados em trânsito (HTTPS/TLS), use variáveis de ambiente ou vaults para armazenar credenciais, e revise regularmente o que é registrado ou retornado em respostas. Implemente redação de dados sensíveis (masking) em logs e erros.

CVE-2024-36509LOWAn exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4EPSS 0.2%CVE-2026-24377MEDIUMWordPress Nexter Blocks plugin <= 4.6.3 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2025-69025MEDIUMWordPress Poptics plugin <= 1.0.20 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2025-62143MEDIUMWordPress Post Video Players plugin <= 1.163 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2025-23382MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Information to an UnauthoEPSS 0.2%CVE-2026-25023MEDIUMWordPress Run Contests, Raffles, and Giveaways with ContestsWP plugin <= 2.0.7 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2025-43406MEDIUMA logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive userEPSS 0.2%CVE-2025-0056MEDIUMInformation Disclosure vulnerability in SAP GUI for JavaEPSS 0.2%CVE-2026-24314MEDIUMInformation Disclosure vulnerability in S/4HANA (Manage Payment Media)EPSS 0.2%CVE-2025-12779HIGHImproper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authEPSS 0.2%CVE-2026-65564MEDIUMWordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2026-66438MEDIUMWordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2026-49077MEDIUMWordPress WP eMember plugin <= v10.2.2 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2024-53683MEDIUMOssur Mobile Logic Application Exposure of Sensitive System Information to an Unauthorized Control SphereEPSS 0.2%CVE-2026-39572MEDIUMWordPress Bus Ticket Booking with Seat Reservation plugin < 5.6.5 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2026-39566MEDIUMWordPress DirectoryPress plugin <= 3.6.26 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2026-44743LOWSecurity Misconfiguration vulnerability in SAP Business ObjectsEPSS 0.2%CVE-2025-0059MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)EPSS 0.2%CVE-2022-50237MEDIUMThe ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a sEPSS 0.2%CVE-2025-53862LOWAap: aap-gateway: automation-hub: sensitive information disclosureEPSS 0.2%