Fallos del tipo CWE-1336

254 resultados

Divulgação de Informação

É quando a aplicação expõe dados sensíveis (senhas, tokens, chaves, informações pessoais) a quem não deveria ter acesso. Pode acontecer por erros de configuração, logs inadequados, respostas de erro verbosas ou falta de controle de acesso. O risco é que um atacante ou usuário não autorizado consegue informações que permitem escalar o ataque ou comprometer contas e sistemas.

Ejemplo

Um site de e-commerce que retorna mensagens de erro com stack trace completo contendo caminhos de arquivo e versões de bibliotecas; ou uma API que inclui tokens de sessão em URLs que ficam registradas em logs do servidor web visíveis a outros usuários.

Cómo mitigar

Implemente controle de acesso rigoroso em dados sensíveis, retorne mensagens de erro genéricas para usuários finais (mantendo logs detalhados apenas internamente), remova informações desnecessárias de respostas HTTP, e audite regularmente o que está sendo exposto em logs, comentários de código e configurações.

CVE-2023-41047MEDIUMImproper Neutralization of Special Elements Used in a Template Engine in OctoPrintEPSS 0.6%CVE-2026-65974CRITICALERPNext: Server-Side Template Injection leading to Remote Code ExecutionEPSS 0.6%CVE-2026-34906CRITICALServer-Side Template Injection (SSTI) in Wirtualna UczelniaEPSS 0.6%CVE-2026-28695HIGHCraft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadgetEPSS 0.6%CVE-2026-77136CRITICALServer-Side Template Injection in extension "powermail" (powermail)EPSS 0.6%CVE-2026-69118HIGHCachet 2.4.1 Authenticated Server-Side Template Injection RCEEPSS 0.6%CVE-2026-55559CRITICALYamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)EPSS 0.6%CVE-2026-37004CRITICALBerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arEPSS 0.5%CVE-2023-5764HIGHAnsible: template injectionEPSS 0.5%CVE-2026-29207MEDIUMApache OFBiz: Low-Privilege SSTI Leading to RCE in the Content ComponentEPSS 0.5%CVE-2024-58303HIGHFoF Pretty Mail 1.1.2 Server Side Template Injection via Email Template SettingsEPSS 0.5%CVE-2025-65602CRITICALA template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a craEPSS 0.5%CVE-2026-44129HIGHServer-side template injectionEPSS 0.5%CVE-2024-46366HIGHA Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side teEPSS 0.5%CVE-2026-28784HIGHCraft is affected by potential authenticated Remote Code Execution via Twig SSTIEPSS 0.5%CVE-2026-33154HIGHdynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja ResolverEPSS 0.5%CVE-2026-47690HIGHMeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflowEPSS 0.5%CVE-2026-39980CRITICALOpenCTI affected by RCE via notifier templateEPSS 0.5%CVE-2024-56326MEDIUMJinja has a sandbox breakout through indirect reference to format methodEPSS 0.5%CVE-2026-47752CRITICALTugtainer has Server-Side Template Injection in notification templates that leads to Remote Code ExecutionEPSS 0.5%