Fallos del tipo CWE-1336

256 resultados

Divulgação de Informação

É quando a aplicação expõe dados sensíveis (senhas, tokens, chaves, informações pessoais) a quem não deveria ter acesso. Pode acontecer por erros de configuração, logs inadequados, respostas de erro verbosas ou falta de controle de acesso. O risco é que um atacante ou usuário não autorizado consegue informações que permitem escalar o ataque ou comprometer contas e sistemas.

Ejemplo

Um site de e-commerce que retorna mensagens de erro com stack trace completo contendo caminhos de arquivo e versões de bibliotecas; ou uma API que inclui tokens de sessão em URLs que ficam registradas em logs do servidor web visíveis a outros usuários.

Cómo mitigar

Implemente controle de acesso rigoroso em dados sensíveis, retorne mensagens de erro genéricas para usuários finais (mantendo logs detalhados apenas internamente), remova informações desnecessárias de respostas HTTP, e audite regularmente o que está sendo exposto em logs, comentários de código e configurações.

CVE-2025-49828HIGHConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Remote Code ExecutionEPSS 2.1%CVE-2023-34252HIGHGrav Server-side Template Injection via Insufficient Validation in filterFilterEPSS 2.1%CVE-2023-34253HIGHGrav vulnerable to Server-side Template Injection (SSTI) via Denylist BypassEPSS 2.1%CVE-2023-2017HIGHImproper Control of Generation of Code in Twig Rendered Views in ShopwareEPSS 2.1%CVE-2026-28496CRITICALFOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCEEPSS 1.9%CVE-2021-39128HIGHAffected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA AdministrEPSS 1.9%CVE-2025-1040HIGHServer-Side Template Injection (SSTI) in significant-gravitas/autogptEPSS 1.7%CVE-2025-49136CRITICALlistmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege userEPSS 1.5%CVE-2023-46245HIGHKimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig FileEPSS 1.5%CVE-2025-46731HIGHCraft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTIEPSS 1.4%CVE-2022-0896HIGHImproper Neutralization of Special Elements Used in a Template Engine in microweber/microweberEPSS 1.4%CVE-2026-21450HIGHBagisto has SSTI in parameter that can lead to RCEEPSS 1.4%CVE-2024-12583CRITICALDynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template InjectionEPSS 1.4%CVE-2023-29297CRITICALAdmin-to-admin stored XSS via cache poisoningEPSS 1.4%CVE-2024-45053CRITICALRemote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating EngineEPSS 1.3%CVE-2023-6743HIGHUnlimited Elements for Elementor <= 1.5.89 - Authenticated(Contributor+) Remote Code Execution via template importEPSS 1.3%CVE-2026-73299CRITICALPrompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks RendererEPSS 1.2%CVE-2026-27641CRITICALFlask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template InjectionEPSS 1.2%CVE-2024-41950HIGHInsecure Jinja2 templates rendered in Haystack Components can lead to RCEEPSS 1.2%CVE-2024-30372HIGHAllegra getLinkText Server-Side Template Injection Remote Code Execution VulnerabilityEPSS 1.2%