Fallos del tipo CWE-1336

254 resultados

Divulgação de Informação

É quando a aplicação expõe dados sensíveis (senhas, tokens, chaves, informações pessoais) a quem não deveria ter acesso. Pode acontecer por erros de configuração, logs inadequados, respostas de erro verbosas ou falta de controle de acesso. O risco é que um atacante ou usuário não autorizado consegue informações que permitem escalar o ataque ou comprometer contas e sistemas.

Ejemplo

Um site de e-commerce que retorna mensagens de erro com stack trace completo contendo caminhos de arquivo e versões de bibliotecas; ou uma API que inclui tokens de sessão em URLs que ficam registradas em logs do servidor web visíveis a outros usuários.

Cómo mitigar

Implemente controle de acesso rigoroso em dados sensíveis, retorne mensagens de erro genéricas para usuários finais (mantendo logs detalhados apenas internamente), remova informações desnecessárias de respostas HTTP, e audite regularmente o que está sendo exposto em logs, comentários de código e configurações.

CVE-2023-27995HIGHA improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an auEPSS 1.1%CVE-2026-22244HIGHOpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEEPSS 1.1%CVE-2024-32406HIGHServer-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code viaEPSS 1.1%CVE-2025-67843HIGHA Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attacEPSS 1.1%CVE-2026-40478CRITICALImproper neutralization of specific syntax patterns for unauthorized expressions in ThymeleafEPSS 1.1%CVE-2023-2259CRITICALImproper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.ioEPSS 1.1%CVE-2026-28697CRITICALCraft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig TemplatesEPSS 1.1%CVE-2024-37301HIGHdocument-merge-service vulnerable to Remote Code Execution via Server-Side Template InjectionEPSS 1.0%CVE-2023-6709CRITICALImproper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflowEPSS 0.9%CVE-2026-21448HIGHBagisto has Normal & Blind SSTI from low-privilege user when ordering productEPSS 0.9%CVE-2025-68454MEDIUMCraft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTIEPSS 0.9%CVE-2026-94109HIGHopenEQUELLA < 2026.1.0 Authenticated Stored SSTI via FreemarkerPortletRendererEPSS 0.9%CVE-2021-4315MEDIUMNYUCCL psiTurk experiment.py special elements used in a template engineEPSS 0.9%CVE-2025-32461CRITICALwikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are EPSS 0.9%CVE-2026-25526CRITICALJinJava Bypass through ForTag leads to Arbitrary Java ExecutionEPSS 0.9%CVE-2025-62369HIGHXibo CMS: Remote Code Execution through module templatesEPSS 0.9%CVE-2025-57811MEDIUMCraft Potential Remote Code Execution via Twig SSTIEPSS 0.9%CVE-2024-42355HIGHShopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagEPSS 0.9%CVE-2024-25624MEDIUMiris-web vulnerable to Server Side Template Injection in reportsEPSS 0.9%CVE-2026-40477CRITICALImproper restriction of the scope of accessible objects in Thymeleaf expressionsEPSS 0.9%