Fallos del tipo CWE-200

4898 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2021-31173MEDIUMMicrosoft SharePoint Server Information Disclosure VulnerabilityEPSS 2.1%CVE-2026-34474HIGHSensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interEPSS 2.1%CVE-2020-24406LOWDocument root path disclosure on Maintenance pageEPSS 2.1%CVE-2025-50738CRITICALThe Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo contEPSS 2.1%CVE-2021-30168CRITICALMERIT LILIN ENT.CO.,LTD. P2/Z2/P3/Z3 IP camera - Sensitive Data Exposure-1EPSS 2.1%CVE-2021-44702LOWAdobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) for Internet Explorer LoadFile NTLMv2 SSO Auth leak vulnerabilityEPSS 2.1%CVE-2021-44739LOWAdobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) src NTLMv2 SSO Auth leak vulnerabilityEPSS 2.1%CVE-2023-36894MEDIUMMicrosoft SharePoint Server Information Disclosure VulnerabilityEPSS 2.1%CVE-2021-20228—A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature whenEPSS 2.1%CVE-2023-6266HIGHBackup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information ExposureEPSS 2.1%CVE-2022-29165CRITICALArgo CD will blindly trust JWT claims if anonymous access is enabledEPSS 2.1%CVE-2019-0202—The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versionEPSS 2.0%CVE-2026-33829MEDIUMWindows Snipping Tool Spoofing VulnerabilityEPSS 2.0%CVE-2024-1210MEDIUMLearnDash LMS <= 4.10.1 - Sensitive Information Exposure via APIEPSS 2.0%CVE-2017-6651—A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to acEPSS 2.0%CVE-2023-40600MEDIUMWordPress EWWW Image Optimizer Plugin <= 7.2.0 is vulnerable to Sensitive Data ExposureEPSS 2.0%CVE-2021-21817HIGHAn information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially craftedEPSS 2.0%CVE-2023-29348HIGHWindows Remote Desktop Gateway (RD Gateway) Information Disclosure VulnerabilityEPSS 2.0%CVE-2023-40712—Apache Airflow: Secrets can be unmasked in the "Rendered Template" EPSS 2.0%CVE-2019-1908HIGHCisco Integrated Management Controller Information Disclosure VulnerabilityEPSS 2.0%