Weaknesses of type CWE-668

236 results

Divulgação de informações

O software expõe dados sensíveis (credenciais, tokens, dados pessoais, configs internas) a uma entidade não autorizada — seja por acesso direto, mensagens de erro verbosas, logs mal protegidos ou canais inseguros. É a falha de um controle de acesso ou encriptação que deveria manter esses dados privados.

Example

Uma API REST que retorna a senha do usuário em plain text na resposta de login; ou um servidor que deixa arquivos de backup (.sql, .env) acessíveis via web; ou um log de erro que exibe URLs internas e tokens de autenticação em páginas públicas.

How to mitigate

Classifique dados por sensibilidade, nunca exponha em respostas de erro ou logs públicos. Use encriptação em trânsito (TLS) e em repouso, aplique controle de acesso rigoroso aos arquivos sensíveis, e revise regularmente o que seu código imprime em mensagens e registros.

CVE-2020-26261HIGHuser-readable api tokens in systemd unitsEPSS 0.5%CVE-2025-23205MEDIUM`frame-ancestors: self` grants all users access to formgrader in nbgraderEPSS 0.5%CVE-2023-39040MEDIUMAn information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.5%CVE-2026-14960CRITICALCVE-2026-14960EPSS 0.5%CVE-2023-39046MEDIUMAn information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.5%CVE-2019-9011MEDIUMIn Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.EPSS 0.4%CVE-2026-30912HIGHApache Airflow: Exposing stack trace in case of constraint errorEPSS 0.4%CVE-2022-41874LOWTauri Filesystem Scope can be Partially BypassedEPSS 0.4%CVE-2026-72764MEDIUMn8n before 1.123.67 Module Cache Poisoning via Code NodeEPSS 0.4%CVE-2026-56077HIGHPraisonAI - Information Disclosure via Shared MultiAgentLedger StateEPSS 0.4%CVE-2023-42716HIGHIn telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional executionEPSS 0.4%CVE-2023-45145LOWRedis Unix-domain socket may have be exposed with the wrong permissions for a short time window.EPSS 0.4%CVE-2022-32530MEDIUMA CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong seEPSS 0.4%CVE-2026-24473MEDIUMHono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)EPSS 0.4%CVE-2024-51754LOWUnguarded calls to __toString() when nesting an object into an array in TwigEPSS 0.4%CVE-2026-14611MEDIUMDeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resourceEPSS 0.4%CVE-2024-51755LOWUnguarded calls to __isset() and to array-accesses when the sandbox is enabled in TwigEPSS 0.4%CVE-2026-32690LOWApache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1EPSS 0.4%CVE-2026-28806CRITICALImproper authorization in device bulk actions and device update API allows cross-organization device controlEPSS 0.4%CVE-2026-53648MEDIUMFOSSBilling: Downloadable product files can be overwritten through filename collisionsEPSS 0.4%