Fallos del tipo CWE-200

4952 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-50950LOWIBM QRadar information disclosureEPSS 0.4%CVE-2026-15627MEDIUMnextlevelbuilder GoClaw tool.go handleNavigate information disclosureEPSS 0.4%CVE-2025-50708HIGHAn issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chatEPSS 0.4%CVE-2025-0226MEDIUMTsinghua Unigroup Electronic Archives System downLoad.html download information disclosureEPSS 0.4%CVE-2024-24817MEDIUMUser can see invitees in events created in PMs and private categoriesEPSS 0.4%CVE-2024-43257MEDIUMWordPress Leopard plugin <= 2.0.36 - Subscriber+ Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2022-32933MEDIUMAn information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be EPSS 0.4%CVE-2024-24845MEDIUMWordPress Post Thumbnail Editor plugin <= 2.4.8 - Unauthenticated Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-7128MEDIUMOpenshift-console: unauthenticated data exposureEPSS 0.4%CVE-2018-10599—IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) REPSS 0.4%CVE-2022-43890MEDIUMIBM Security Verify Privilege On-Premises information disclosureEPSS 0.4%CVE-2024-43251MEDIUMWordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-50554MEDIUMNote Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-markEPSS 0.4%CVE-2026-27131MEDIUMSprig Plugin for Craft CMS potentially discloses sensitive information via Sprig PlaygroundEPSS 0.4%CVE-2024-13829MEDIUMWordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.8 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2024-39817MEDIUMInsertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to thEPSS 0.4%CVE-2024-11153MEDIUMContent Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.4%CVE-2025-32700LOWAbuseFilter log interfaces expose global private and hidden filters when central DB is not availableEPSS 0.4%CVE-2024-33626MEDIUMThe LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive informaEPSS 0.4%CVE-2024-20396MEDIUMA vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive infoEPSS 0.4%