Fallos del tipo CWE-200

4940 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2011-4917—In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.EPSS 0.5%CVE-2026-72915HIGHMastodon: Personally-identifying information disclosure due to incorrect access control validationEPSS 0.5%CVE-2026-19357MEDIUMMingSoft MCMS ms-mdiy get information disclosureEPSS 0.5%CVE-2026-28559MEDIUMwpForo Forum 2.4.14 Information Disclosure via Global RSS FeedEPSS 0.5%CVE-2026-9352MEDIUMNousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosureEPSS 0.5%CVE-2026-25038HIGHGitea private organization labels are visible to unauthorized usersEPSS 0.5%CVE-2026-71862HIGHCheckmate: Sensitive Bearer Token Exposure via Public Status Pages When showURL Setting is EnabledEPSS 0.5%CVE-2024-7413MEDIUMObfuscate Email <= 3.8.1 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2026-8995MEDIUMPoll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX ActionEPSS 0.5%CVE-2024-0616MEDIUMPassster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information ExposureEPSS 0.5%CVE-2022-20776MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.5%CVE-2024-0620MEDIUMPPWP – Password Protect Pages <= 1.8.9 - Protection Mechanism BypassEPSS 0.5%CVE-2024-7410MEDIUMMy Custom CSS PHP & ADS <= 3.3 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2024-7382MEDIUMLinkify Text <= 1.9.1 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2024-7412MEDIUMNo Update Nag <= 1.4.12 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2026-92947CRITICALvm2 before 3.11.7 Memory Disclosure via Buffer PoolEPSS 0.5%CVE-2026-24451HIGHGitea fork synchronization can expose private parent repository dataEPSS 0.5%CVE-2023-52187MEDIUMWordPress Image Source Control Plugin <= 2.17.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-40490MEDIUMAsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirectsEPSS 0.5%CVE-2024-42657HIGHAn issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryEPSS 0.5%