Weaknesses of type CWE-538
93 resultsExposição de informações sensíveis em arquivos acessíveis externamente
A aplicação escreve dados sensíveis (credenciais, tokens, chaves) em arquivos ou diretórios que podem ser acessados por usuários não autorizados. Isso pode ocorrer em logs, caches, arquivos temporários ou diretórios web públicos, expondo informações críticas.
Example
Uma aplicação gera um relatório em PDF com dados de clientes e o salva na pasta /var/www/html (acessível pela web), ou registra tokens de autenticação em um arquivo de log legível por qualquer usuário do sistema.
How to mitigate
Restrinja permissões de arquivo (chmod 600 ou equivalente), nunca escreva dados sensíveis em diretórios públicos, use variáveis de ambiente ou gestores de secrets para credenciais, e implemente rotação/limpeza automática de logs que contenham informações confidenciais.
CVE-2023-46723HIGHlte-pic32-writer's sendto.txt may disclose URL and the API keyEPSS 0.4%CVE-2026-7071MEDIUMCodeAstro Online Job Portal user-cvs file information disclosureEPSS 0.4%CVE-2025-31558MEDIUMWordPress TailPress plugin <= 0.4.4 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-27150MEDIUMTuleap dumps the Redis password into the generated troubleshooting archivesEPSS 0.4%CVE-2025-22306MEDIUMWordPress Link Whisper Free plugin <= 0.7.7 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-22773MEDIUMWordPress Htaccess File Editor <= 1.0.19 - Broken Authentication vulnerabilityEPSS 0.4%CVE-2026-46617HIGHFission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap readEPSS 0.3%CVE-2025-22633MEDIUMWordPress Give – Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-10254MEDIUMSourceCodester Pet Grooming Management Software admin file information disclosureEPSS 0.3%CVE-2026-19229MEDIUMSourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosureEPSS 0.3%CVE-2025-12059CRITICALImproper Access Control in Logo Software's Logo j-PlatformEPSS 0.3%CVE-2022-23508HIGHGitOps Run allows for Kubernetes workload injectionEPSS 0.3%CVE-2025-24689MEDIUMWordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2023-54346HIGHWordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup DownloadEPSS 0.3%CVE-2025-11891MEDIUMShelf Planner <= 2.8.1 - Unauthenticated Information Exposure via Log FilesEPSS 0.3%CVE-2025-58458MEDIUMIn Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the EPSS 0.3%CVE-2026-6160MEDIUMcode-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disclosureEPSS 0.3%CVE-2025-31421MEDIUMWordPress Srbtranslatin plugin <= 3.2.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-36372MEDIUMIBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tablesEPSS 0.3%CVE-2025-61138HIGHQlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.EPSS 0.3%