Fallos del tipo CWE-200

4898 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2021-41532—Unauthenticated access to Ozone Recon HTTP endpointsEPSS 2.4%CVE-2026-2262HIGHEasy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 2.4%CVE-2021-39856MEDIUMAdobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via LoadFileEPSS 2.4%CVE-2021-39855MEDIUMAdobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via src ParameterEPSS 2.4%CVE-2025-9209CRITICALRestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWTEPSS 2.3%CVE-2025-12139HIGHFile Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information ExposureEPSS 2.3%CVE-2017-6626—A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allowEPSS 2.3%CVE-2020-8216—An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting detailsEPSS 2.3%CVE-2018-0245—A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote EPSS 2.3%CVE-2026-34472HIGHUnauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attacEPSS 2.3%CVE-2024-12008MEDIUMW3 Total Cache <= 2.8.1 Information Exposure via Log FilesEPSS 2.3%CVE-2021-21323MEDIUMRegression in DNS leakage from Tor windowsEPSS 2.3%CVE-2017-12354—A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to viEPSS 2.2%CVE-2024-8929MEDIUMLeak partial content of the heap through heap buffer over-read in mysqlndEPSS 2.2%CVE-2026-4020HIGHGravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 2.2%CVE-2020-15098HIGHMissing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMSEPSS 2.2%CVE-2022-23633HIGHExposure of sensitive information in Action PackEPSS 2.2%CVE-2020-8151—There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requestEPSS 2.2%CVE-2020-3411HIGHCisco DNA Center Information Disclosure VulnerabilityEPSS 2.2%CVE-2023-28322MEDIUMAn information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callbackEPSS 2.2%