Fallos del tipo CWE-1336

254 resultados

Divulgação de Informação

É quando a aplicação expõe dados sensíveis (senhas, tokens, chaves, informações pessoais) a quem não deveria ter acesso. Pode acontecer por erros de configuração, logs inadequados, respostas de erro verbosas ou falta de controle de acesso. O risco é que um atacante ou usuário não autorizado consegue informações que permitem escalar o ataque ou comprometer contas e sistemas.

Ejemplo

Um site de e-commerce que retorna mensagens de erro com stack trace completo contendo caminhos de arquivo e versões de bibliotecas; ou uma API que inclui tokens de sessão em URLs que ficam registradas em logs do servidor web visíveis a outros usuários.

Cómo mitigar

Implemente controle de acesso rigoroso em dados sensíveis, retorne mensagens de erro genéricas para usuários finais (mantendo logs detalhados apenas internamente), remova informações desnecessárias de respostas HTTP, e audite regularmente o que está sendo exposto em logs, comentários de código e configurações.

CVE-2026-21449HIGHBagisto has SSTI via first and last name from low-privilege user (not admin)EPSS 0.5%CVE-2026-1868CRITICALImproper Neutralization of Special Elements Used in a Template Engine in GitLab AI GatewayEPSS 0.5%CVE-2025-65106HIGHLangChain Vulnerable to Template Injection via Attribute Access in Prompt TemplatesEPSS 0.5%CVE-2026-92592HIGHCraft CMS before 4.18.6 Remote Code Execution via signed cookieEPSS 0.5%CVE-2026-89094CRITICALForgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/templatEPSS 0.5%CVE-2025-66438CRITICALA Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. SpecifiEPSS 0.5%CVE-2022-23851CRITICALNetaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).EPSS 0.5%CVE-2025-27516MEDIUMJinja sandbox breakout through attr filter selecting format methodEPSS 0.5%CVE-2025-5325MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testService special elements used in a template engineEPSS 0.5%CVE-2025-68929CRITICALFrappe may be vulnerable remote code execution due to server-side template injectionEPSS 0.5%CVE-2022-4993CRITICALHTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation templateEPSS 0.5%CVE-2026-33654HIGHZero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingEPSS 0.5%CVE-2025-2040MEDIUMzhijiantianya ruoyi-vue-pro deploy special elements used in a template engineEPSS 0.5%CVE-2024-9150HIGHCode Injection in Wyn EnterpriseEPSS 0.5%CVE-2026-33897CRITICALIncus vulnerable to arbitrary file read and write through pongo templatesEPSS 0.5%CVE-2026-71871CRITICALOrval: Import-time RCE via header-parameter default -> zod module-level template literalEPSS 0.5%CVE-2026-66613CRITICALWordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2026-91925HIGHPolyaxon through 2.16.4 Server-Side Template Injection via Unsandboxed Jinja2 EngineEPSS 0.5%CVE-2022-27662MEDIUMOn F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exiEPSS 0.5%CVE-2026-45697CRITICALFormie: Pre-authenticated server-side template injection in Hidden fieldsEPSS 0.5%