Weaknesses of type CWE-668

235 results

Divulgação de informações

O software expõe dados sensíveis (credenciais, tokens, dados pessoais, configs internas) a uma entidade não autorizada — seja por acesso direto, mensagens de erro verbosas, logs mal protegidos ou canais inseguros. É a falha de um controle de acesso ou encriptação que deveria manter esses dados privados.

Example

Uma API REST que retorna a senha do usuário em plain text na resposta de login; ou um servidor que deixa arquivos de backup (.sql, .env) acessíveis via web; ou um log de erro que exibe URLs internas e tokens de autenticação em páginas públicas.

How to mitigate

Classifique dados por sensibilidade, nunca exponha em respostas de erro ou logs públicos. Use encriptação em trânsito (TLS) e em repouso, aplique controle de acesso rigoroso aos arquivos sensíveis, e revise regularmente o que seu código imprime em mensagens e registros.

CVE-2023-42792Apache Airflow: Improper access control to DAG resourcesEPSS 1.4%CVE-2022-35936HIGHEthermint DoS through Unintended Contract SelfdestructEPSS 1.4%CVE-2021-44522A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.EPSS 1.4%CVE-2021-44523A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.EPSS 1.4%CVE-2023-29355MEDIUMDHCP Server Service Information Disclosure VulnerabilityEPSS 1.3%CVE-2023-31103HIGHApache InLong: Attackers can change the immutable name and type of clusterEPSS 1.3%CVE-2023-34189Apache InLong: General user can delete and update processEPSS 1.3%CVE-2020-5386HIGHDell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list oEPSS 1.3%CVE-2023-31206HIGHApache InLong: Attackers can change the immutable name and type of nodesEPSS 1.2%CVE-2022-45438MEDIUMApache Superset: Dashboard metadata information leakEPSS 1.2%CVE-2023-26081HIGHIn Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandEPSS 1.2%CVE-2021-21878MEDIUMA local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0EPSS 1.2%CVE-2021-22869Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupEPSS 1.2%CVE-2021-23264HIGHTransmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter SearchEPSS 1.1%CVE-2022-22515HIGHA component of the CODESYS Control runtime system allows read and write access to configuration filesEPSS 1.1%CVE-2022-48198CRITICALThe ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code oEPSS 1.1%CVE-2023-39171HIGHSENEC Storage Box V1,V2 and V3 accidentially expose a management interfaceEPSS 1.1%CVE-2022-24074Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itEPSS 1.1%CVE-2021-39184MEDIUMSandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIEPSS 1.1%CVE-2022-24823MEDIUMLocal Information Disclosure Vulnerability in io.netty:netty-codec-httpEPSS 1.0%