Fallos del tipo CWE-200

4948 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-24373MEDIUMUnrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slipsEPSS 0.4%CVE-2025-70829MEDIUMAn information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC conEPSS 0.4%CVE-2024-12140MEDIUMElementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements <= 2.2.1 - Authenticated (Contributor+) Private Templates Content DisclosureEPSS 0.4%CVE-2021-46891—Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2021-36096MEDIUMSupport Bundle includes S/Mime and PGP secret or PINEPSS 0.4%CVE-2023-41676MEDIUMAn exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker wEPSS 0.4%CVE-2026-9836LOWIBM DataStage Flow Designer application is affected by an information disclosure vulnerabilityEPSS 0.4%CVE-2020-9846—A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be ablEPSS 0.4%CVE-2024-6570MEDIUMGlossary <= 2.2.26 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-84135CRITICALOther issue in Firefox Focus for AndroidEPSS 0.4%CVE-2026-54553MEDIUMStarlette-Admin: Unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoSEPSS 0.4%CVE-2024-6567MEDIUMEbook Store <= 5.8001 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-34984HIGHExternal Secrets Operator has DNS exfiltration via getHostByName in its v2 template engineEPSS 0.4%CVE-2024-6546MEDIUMOne Click Close Comments <= 2.7.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-43289HIGHWordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2023-3455—Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.EPSS 0.4%CVE-2026-78378MEDIUMRedis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook DataEPSS 0.4%CVE-2024-38761HIGHWordPress Zephyr Project Manager plugin <= 3.3.99 - Sensitive Data Exposure via Export File vulnerabilityEPSS 0.4%CVE-2024-38747HIGHWordPress HitPay Payment Gateway for WooCommerce plugin <= 4.1.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-13525MEDIUMCustomer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%