Fallos del tipo CWE-200

4953 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-5059MEDIUMWordPress Event Monster Plugin <= 1.4.0 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-32963MEDIUMParameter Tampering vulnerability in NavidromeEPSS 0.4%CVE-2026-42151HIGHPrometheus Azure AD remote write OAuth client secret exposed via config APIEPSS 0.4%CVE-2025-68279HIGHWeblate has an arbitrary file read via symbolic linksEPSS 0.4%CVE-2026-7526MEDIUMPDF Embedder <= 4.9.3 - Authenticated (Contributor+) Information Exposure via Block Editor PageEPSS 0.4%CVE-2023-28357MEDIUMA vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is aEPSS 0.4%CVE-2022-31746MEDIUMInternal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability aEPSS 0.4%CVE-2026-73604HIGHFlowise before 3.1.3 Credential Exposure via APIEPSS 0.4%CVE-2026-12385MEDIUMSmart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' ParameterEPSS 0.4%CVE-2026-3691MEDIUMOpenClaw Client PKCE Verifier Information Disclosure VulnerabilityEPSS 0.4%CVE-2011-4916—Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.EPSS 0.4%CVE-2026-7544MEDIUMMux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information ExposureEPSS 0.4%CVE-2026-4126MEDIUMTable Manager <= 1.0.0 - Authenticated (Contributor+) Sensitive Information Exposure via 'table' Shortcode AttributeEPSS 0.4%CVE-2025-32983HIGHNETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.EPSS 0.4%CVE-2024-11741MEDIUMGrafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected EPSS 0.4%CVE-2026-44231CRITICALRT: Privilege escalation and information disclosure via REST 2.0 user collection endpointEPSS 0.4%CVE-2026-32237MEDIUM@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpointEPSS 0.4%CVE-2025-54373HIGHOpenEMR may expose Contents of Clinical Notes and Care Planto users who do not have Sensitivities=high privilegeEPSS 0.4%CVE-2026-67529MEDIUMOpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)EPSS 0.4%CVE-2026-35038LOWsignalk-server: Arbitrary Prototype Read via `from` Field BypassEPSS 0.4%