Weaknesses of type CWE-93

207 results

Divulgação de Informações

Fraqueza genérica que engloba qualquer falha onde dados sensíveis (credenciais, tokens, caminhos internos, versões de software) são expostos a usuários ou atacantes que não deveriam ter acesso. O risco varia conforme a sensibilidade da informação vazada e o contexto de exposição.

Example

Um aplicativo web mostra mensagens de erro detalhadas contendo stack traces com paths absolutos do servidor, ou um arquivo de configuração versionado no Git expõe chaves de API. Um atacante coleta essas informações para mapear a infraestrutura ou comprometer credenciais.

How to mitigate

Implemente tratamento genérico de erros (sem revelar detalhes técnicos ao usuário final), remova dados sensíveis de logs públicos, revise permissões de arquivo de configuração, use .gitignore para arquivos sensíveis, e estabeleça reviews regulares de what's exposed em respostas HTTP e mensagens de erro.

CVE-2023-26130HIGHVersions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the contEPSS 1.1%CVE-2018-12477LOWobs-service-refresh_patches can be tricked into deleting '..' or other unrelated directoriesEPSS 1.1%CVE-2026-82854CRITICALNodemailer before 8.0.3 SMTP Command Injection via envelope.sizeEPSS 1.1%CVE-2023-23936MEDIUMCRLF Injection in Nodejs ‘undici’ via hostEPSS 1.1%CVE-2026-30227MEDIUMMimeKit: CRLF Injection in Quoted Local-Part Enables SMTP Command Injection and Email ForgeryEPSS 1.1%CVE-2026-42578LOWNetty: HTTP Header Injection via HttpProxyHandler Disabled ValidationEPSS 1.1%CVE-2023-38551HIGHA CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code onEPSS 1.0%CVE-2026-39849HIGHPi-hole FTL remote code execution via newline injection in dns.interface configurationEPSS 1.0%CVE-2023-49082MEDIUMaiohttp's ClientSession is vulnerable to CRLF injection via methodEPSS 0.9%CVE-2024-51981MEDIUMUnauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and Toshiba Tec, and Konica Minolta, Inc.EPSS 0.9%CVE-2026-57281HIGHJenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions mEPSS 0.9%CVE-2020-3246MEDIUMCisco Umbrella Carriage Return Line Feed Injection VulnerabilityEPSS 0.9%CVE-2020-15111MEDIUMCRLF vulnerability in FiberEPSS 0.9%CVE-2026-35517HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline InjectionEPSS 0.9%CVE-2021-4097MEDIUMCRLF Injection in phpservermon/phpservermonEPSS 0.8%CVE-2026-15429MEDIUMPrivilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800vEPSS 0.8%CVE-2026-42258MEDIUMnet-imap: Command Injection via unvalidated Symbol inputsEPSS 0.8%CVE-2019-15616Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.EPSS 0.8%CVE-2025-27111MEDIUMEscape Sequence Injection vulnerability in Rack lead to Possible Log InjectionEPSS 0.7%CVE-2026-82853MEDIUMNodemailer before 8.0.5 SMTP Command Injection via CRLFEPSS 0.7%