Weaknesses of type CWE-538
93 resultsExposição de informações sensíveis em arquivos acessíveis externamente
A aplicação escreve dados sensíveis (credenciais, tokens, chaves) em arquivos ou diretórios que podem ser acessados por usuários não autorizados. Isso pode ocorrer em logs, caches, arquivos temporários ou diretórios web públicos, expondo informações críticas.
Example
Uma aplicação gera um relatório em PDF com dados de clientes e o salva na pasta /var/www/html (acessível pela web), ou registra tokens de autenticação em um arquivo de log legível por qualquer usuário do sistema.
How to mitigate
Restrinja permissões de arquivo (chmod 600 ou equivalente), nunca escreva dados sensíveis em diretórios públicos, use variáveis de ambiente ou gestores de secrets para credenciais, e implemente rotação/limpeza automática de logs que contenham informações confidenciais.
CVE-2022-4318HIGHCri-o: /etc/passwd tampering privescEPSS 0.3%CVE-2022-20864MEDIUMCisco IOS XE ROM Monitor Software for Catalyst Switches Information Disclosure VulnerabilityEPSS 0.3%CVE-2018-4847—A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive informaEPSS 0.3%CVE-2022-43933MEDIUMconfiguration secrets are logged in support-saveEPSS 0.3%CVE-2025-68429HIGHStorybook manager bundle may expose environment variables during buildEPSS 0.3%CVE-2026-50565MEDIUMFission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder containerEPSS 0.3%CVE-2026-33705MEDIUMChamilo LMS has unauthenticated access to Twig template source files exposes application logicEPSS 0.2%CVE-2025-8452MEDIUMUnauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., Toshiba Tec, and Konica Minolta, Inc.EPSS 0.2%CVE-2026-12762MEDIUMInsertion of Sensitive Information into Externally-Accessible File in IBM Business Automation InsightsEPSS 0.2%CVE-2026-21672HIGHA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.EPSS 0.2%CVE-2022-0013MEDIUMCortex XDR Agent: File Information Exposure Vulnerability When Generating Support FileEPSS 0.2%CVE-2026-5434MEDIUMImproper storage of sensitive informationEPSS 0.2%CVE-2024-31954HIGHAn issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directoEPSS 0.2%CVE-2019-25717MEDIUMDräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File DisclosureEPSS 0.2%CVE-2026-29114LOWA vulnerability has been found in some Dahua products. An attacker
may obtain the device’s CA root certificate. If that CA is installed and
EPSS 0.2%CVE-2025-46820HIGHphpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifactEPSS 0.2%CVE-2025-12699MEDIUMZOLL ePCR IOS Mobile Application Insertion of Sensitive Information into Externally-Accessible File or DirectoryEPSS 0.2%CVE-2023-38558MEDIUMA vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration ConsoleEPSS 0.2%CVE-2026-50099MEDIUMNaxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directoryEPSS 0.2%CVE-2026-57442MEDIUMMCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nestedEPSS 0.2%