Fallos del tipo CWE-200

4898 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2017-6645—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2017-6643—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2026-5032HIGHW3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent HeaderEPSS 2.7%CVE-2014-0786—Ecava IntegraXor Information ExposureEPSS 2.6%CVE-2023-39508HIGHApache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledgesEPSS 2.6%CVE-2026-39363HIGHVite Affected by Arbitrary File Read via Vite Dev Server WebSocketEPSS 2.6%CVE-2018-0288—A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access sensitive data about EPSS 2.6%CVE-2004-2320MEDIUMThe default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13EPSS 2.6%CVE-2022-24853MEDIUMFile system exposure in MetabaseEPSS 2.5%CVE-2026-27886CRITICALStrapi may leak sensitive data via relational filtering due to lack of query sanitizationEPSS 2.5%CVE-2021-39857MEDIUMAdobe Acrobat Reader DC Information Disclosure via ActiveX LoadFileEPSS 2.5%CVE-2022-1077MEDIUMTEM FLEX-1080/FLEX-1085 Log information disclosureEPSS 2.5%CVE-2022-22547—Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted EPSS 2.5%CVE-2018-16876LOWansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leEPSS 2.5%CVE-2026-41492CRITICALUnauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in DgraphEPSS 2.5%CVE-2022-0725—A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information ExpoEPSS 2.5%CVE-2023-32561HIGHA previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authenticaEPSS 2.4%CVE-2019-7619—Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated aEPSS 2.4%CVE-2014-2347—AMTELCO miSecure Information ExposureEPSS 2.4%CVE-2024-1209MEDIUMLearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignmentsEPSS 2.4%