Fallos del tipo CWE-200

4952 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-78174CRITICALWatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsEPSS 0.4%CVE-2026-42871MEDIUMWeGIA: Error Handling familiar_docfamiliarEPSS 0.4%CVE-2023-34442—Apache Camel JIRA: Temporary file information disclosure in Camel-JiraEPSS 0.4%CVE-2026-60031MEDIUMJoomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1EPSS 0.4%CVE-2026-47379MEDIUMNocoDB: Plaintext Password Comparison in Shared ViewsEPSS 0.4%CVE-2022-27891MEDIUMPalantir Gotham included an unauthenticated endpoint that listed all active usernames in the platform with an active session. EPSS 0.4%CVE-2026-77132MEDIUMTYPO3 CMS - Information Disclosure via Backend Localization WizardEPSS 0.4%CVE-2026-59503CRITICALPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.4%CVE-2025-32986HIGHNETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.EPSS 0.4%CVE-2020-10750HIGHSensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store EPSS 0.4%CVE-2024-45040MEDIUMgnark's commitments to private witnesses in Groth16 as implemented break zero-knowledge propertyEPSS 0.4%CVE-2026-85055HIGHTwenty: Field-level read bypassEPSS 0.4%CVE-2026-73082MEDIUMActivepieces: Server-side request forgery in MCP tool validation endpointEPSS 0.4%CVE-2026-58442MEDIUMRepository migration SSRF via multi-answer DNS allow-list bypassEPSS 0.4%CVE-2026-1170MEDIUMbirkir prime GraphQL API graphql information disclosureEPSS 0.4%CVE-2025-68110CRITICALChurchCRM discloses database information on error messageEPSS 0.4%CVE-2024-6407CRITICALCWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to thEPSS 0.4%CVE-2026-33761MEDIUMAVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User MappingsEPSS 0.4%CVE-2022-0850—A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.EPSS 0.4%CVE-2025-14507MEDIUMEventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 0.4%