Fallos del tipo CWE-200

4941 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-39358MEDIUMMetabase vulnerable to circumvention of Locked parameter in Signed EmbeddingEPSS 0.5%CVE-2024-0906MEDIUMf(x) Private Site <= 1.2.1 - Sensitive Information ExposureEPSS 0.5%CVE-2021-46841—This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An EPSS 0.5%CVE-2024-13623MEDIUMOrder Export for WooCommerce <= 3.24 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2025-65820CRITICALAn issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application whicEPSS 0.5%CVE-2026-67100CRITICALHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.5%CVE-2025-59209MEDIUMWindows Push Notification Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-0883MEDIUMInformation disclosure in the Networking componentEPSS 0.5%CVE-2026-24473MEDIUMHono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)EPSS 0.5%CVE-2026-58427HIGHPrivate org member list leaked via /members API endpoint — incomplete fix for PR #38145EPSS 0.5%CVE-2026-51995HIGHAn issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-sEPSS 0.5%CVE-2026-27161HIGHUnauthenticated Information Disclosure via .htaccess Reliance in Sensitive DirectoriesEPSS 0.5%CVE-2023-31404MEDIUMInformation Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)EPSS 0.5%CVE-2024-13604HIGHKB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin <= 1.7.4 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2026-86895HIGHAn information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOSEPSS 0.5%CVE-2026-58434HIGHPrivate Repository Metadata Remains Accessible After Access RevocationEPSS 0.5%CVE-2026-32266LOWGoogle Cloud Storage for Craft CMS has an Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-56267MEDIUMFlowise - PII Disclosure via Unauthenticated Forgot Password EndpointEPSS 0.5%CVE-2022-32244—Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) sysEPSS 0.5%CVE-2026-1196LOWMineAdmin getFileInfoById information disclosureEPSS 0.5%