Fallos del tipo CWE-200

4951 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-48786MEDIUMFleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpointEPSS 0.4%CVE-2026-47364MEDIUMIn versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no userEPSS 0.4%CVE-2026-89278MEDIUMGPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline ScriptEPSS 0.4%CVE-2026-33882MEDIUMStatamic's Markdown preview endpoint exposes sensitive user dataEPSS 0.4%CVE-2024-10312MEDIUMExclusive Addons for Elementor <= 2.7.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.4%CVE-2024-22002HIGHCORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the instaEPSS 0.4%CVE-2026-3504MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API EndpointEPSS 0.4%CVE-2026-88876HIGHAVideo PlayerSkins seo.php Missing Authorization Password-Protected VODEPSS 0.4%CVE-2026-61842MEDIUMGrav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)EPSS 0.4%CVE-2025-49143MEDIUMNautobot may allows uploaded media files to be accessible without authenticationEPSS 0.4%CVE-2023-23628MEDIUMMetabase subject to Exposure of Sensitive Information to an Unauthorized Actor EPSS 0.4%CVE-2026-61133HIGHVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.4%CVE-2026-60393HIGHVulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supportedEPSS 0.4%CVE-2026-73878HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.4%CVE-2024-22435HIGHHPE NonStop Web ViewPoint Enterprise software, Unauthorized accessEPSS 0.4%CVE-2026-61159HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%CVE-2026-60556HIGHVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2026-60554HIGHVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2024-55951MEDIUMMetabase sandboxed users could see filter values from other sandboxed usersEPSS 0.4%CVE-2026-87221HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%