Fallos del tipo CWE-200

4958 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-46813MEDIUMPrivate data leak on login-required Discourse sitesEPSS 0.4%CVE-2026-41954MEDIUMiControl REST and tmsh vulnerabilityEPSS 0.4%CVE-2025-7394HIGHIn the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for prEPSS 0.4%CVE-2024-29885MEDIUMReports are still accessible even when `canView()` returns false in silverstripe/reportsEPSS 0.4%CVE-2024-11282MEDIUMPassster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.4%CVE-2024-7554MEDIUMExposure of Sensitive Information to an Unauthorized Actor in GitLabEPSS 0.4%CVE-2025-59260MEDIUMMicrosoft Failover Cluster Virtual Driver Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-54137HIGHliboqs has a correctness error in HQC decapsulationEPSS 0.4%CVE-2025-2841MEDIUMCart66 Cloud <= 2.3.7 - Unauthenticated Information ExposureEPSS 0.4%CVE-2025-53886MEDIUMDirectus doesn't redact tokens in Flow logsEPSS 0.4%CVE-2024-13820MEDIUMMelhor Envio <= 2.15.11 - Unauthenticated Sensitive Information Exposure via Hardcoded HashEPSS 0.4%CVE-2023-41293—Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.EPSS 0.4%CVE-2024-21152HIGHVulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Allocation Rules). Supported veEPSS 0.4%CVE-2024-9538MEDIUMShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor TemplateEPSS 0.4%CVE-2026-44409MEDIUMInformation disclosure vulnerability in ZTE MU5250EPSS 0.4%CVE-2025-30439MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.EPSS 0.4%CVE-2026-12203MEDIUMHKUDS AI-Trader Research Export agents.csv information disclosureEPSS 0.4%CVE-2025-52467CRITICALpgai secrets exfiltration via `pull_request_target`EPSS 0.4%CVE-2023-43998MEDIUMAn issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel accessEPSS 0.4%CVE-2025-2883MEDIUMAccept SagePay Payments Using Contact Form 7 <= 2.0 - Unauthenticated Information ExposureEPSS 0.4%