Fallos del tipo CWE-200

4949 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-21579HIGHThis High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2EPSS 0.4%CVE-2024-7415MEDIUMRemember Me Controls <= 2.0.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-21685HIGHThis High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. EPSS 0.4%CVE-2024-6499MEDIUMWordPress Button Plugin MaxButtons <= 9.7.8 - Full Path DisclosureEPSS 0.4%CVE-2024-6552MEDIUMBooking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-56242HIGHCapgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPCEPSS 0.4%CVE-2026-93685MEDIUMMulticluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering)EPSS 0.4%CVE-2024-6557MEDIUMSchedulePress <= 5.1.3 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-67972HIGHAn issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possiblyEPSS 0.4%CVE-2026-55088MEDIUMEtherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokenEPSS 0.4%CVE-2025-11670MEDIUMNTLM Hash Exposure VulnerabilityEPSS 0.4%CVE-2026-25222MEDIUMPolarLearn Affected by User Enumeration via Argon2 Timing Attack on Sign-In EndpointEPSS 0.4%CVE-2024-6565MEDIUMAForms <= 2.2.6 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-5614MEDIUMPiotnet Addons For Elementor <= 2.4.29 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-84130HIGHInformation disclosure in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-34579MEDIUMMantisBT has an authorization bypass via private issue monitoringEPSS 0.4%CVE-2022-30735MEDIUMImproper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permissioEPSS 0.4%CVE-2026-89278MEDIUMGPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline ScriptEPSS 0.4%CVE-2026-61842MEDIUMGrav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)EPSS 0.4%CVE-2024-35223MEDIUMDapr API Token ExposureEPSS 0.4%