Fallos del tipo CWE-1336

254 resultados

Divulgação de Informação

É quando a aplicação expõe dados sensíveis (senhas, tokens, chaves, informações pessoais) a quem não deveria ter acesso. Pode acontecer por erros de configuração, logs inadequados, respostas de erro verbosas ou falta de controle de acesso. O risco é que um atacante ou usuário não autorizado consegue informações que permitem escalar o ataque ou comprometer contas e sistemas.

Ejemplo

Um site de e-commerce que retorna mensagens de erro com stack trace completo contendo caminhos de arquivo e versões de bibliotecas; ou uma API que inclui tokens de sessão em URLs que ficam registradas em logs do servidor web visíveis a outros usuários.

Cómo mitigar

Implemente controle de acesso rigoroso em dados sensíveis, retorne mensagens de erro genéricas para usuários finais (mantendo logs detalhados apenas internamente), remova informações desnecessárias de respostas HTTP, e audite regularmente o que está sendo exposto em logs, comentários de código e configurações.

CVE-2026-44723MEDIUMVowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allows arbitrary command execution on CI runnerEPSS 0.5%CVE-2025-53909CRITICALmailcow: dockerized vulnerable to SSTI in Quota and Quarantine Notification TemplateEPSS 0.5%CVE-2026-28783CRITICALCraft has a Twig Function Blocklist BypassEPSS 0.5%CVE-2025-60355CRITICALzhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.EPSS 0.5%CVE-2026-82447HIGHSkyvern before 1.0.45 Sandbox Escape via TextPromptBlockEPSS 0.5%CVE-2026-23626MEDIUMKimai Vulnerable to Authenticated Server-Side Template Injection (SSTI)EPSS 0.5%CVE-2026-13051CRITICALForm::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext templateEPSS 0.5%CVE-2025-14731MEDIUMCTCMS Content Management System Frontend/Template Management CT_Parser.php special elements used in a template engineEPSS 0.4%CVE-2024-54954HIGHOneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.EPSS 0.4%CVE-2026-52762HIGHYesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic TemplatesEPSS 0.4%CVE-2026-54653HIGH`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema fieldEPSS 0.4%CVE-2026-45312CRITICALRAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code ExecutionEPSS 0.4%CVE-2026-77939HIGHFlextype CMS 1.0.0-dev RCE via POST /api/v1/query EndpointEPSS 0.4%CVE-2025-3841MEDIUMwix-incubator jam Jinja2 Template jam.py special elements used in a template engineEPSS 0.4%CVE-2025-10380HIGHAdvanced Views – Display Posts, Custom Fields, and More <= 3.7.19 - Authenticated (Author+) Remote Code Execution via SSTIEPSS 0.4%CVE-2024-27623MEDIUMCMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, pEPSS 0.4%CVE-2025-35113MEDIUMAgiloft improper neutralization in EUI template engineEPSS 0.4%CVE-2026-47727HIGHTrilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass leading to EJS SSTI (Incomplete Fix of CVE-2026-45668)EPSS 0.4%CVE-2026-41065HIGHTautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution via Newsletter Custom Template DirectoryEPSS 0.4%CVE-2026-41901CRITICALThymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressionsEPSS 0.4%