Fallos del tipo CWE-200

4958 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2021-32638MEDIUMCodeQL runner: Command-line options that make GitHub access tokens visible to other processes are now deprecatedEPSS 0.4%CVE-2026-27162MEDIUMDIscourse doesn't prevent whispers to leak in excerptsEPSS 0.4%CVE-2025-10607MEDIUMPortabilis i-Educar diarioApi information disclosureEPSS 0.4%CVE-2024-9540MEDIUMSina Extension for Elementor <= 3.5.7 - Authenticated (Contributor+) Sensitive Information Exposure via Sina Modal Box Widget Elementor TemplateEPSS 0.4%CVE-2025-49593MEDIUMPortainer HTTP Headers May Leak to Malicious Container RegistriesEPSS 0.4%CVE-2024-6757MEDIUMElementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt FunctionEPSS 0.4%CVE-2025-61907HIGHIcinga 2 API users could access restricted values in filter expressionsEPSS 0.4%CVE-2025-37165HIGHExposure of VLAN information in unintended network interfacesEPSS 0.4%CVE-2025-8519MEDIUMgivanz Vvveb Drag-and-Drop Editor editor information disclosureEPSS 0.4%CVE-2023-34250MEDIUMDiscourse vulnerable to exposure of number of topics recently created in private categoriesEPSS 0.4%CVE-2026-10055HIGHIn Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connecteEPSS 0.4%CVE-2026-63746HIGHSurrealDB before 3.1.0 Permission Bypass via Graph TraversalEPSS 0.4%CVE-2026-34091MEDIUMUser localization leaked by AbuseFilter + EventStreamEPSS 0.4%CVE-2023-39383—Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromisEPSS 0.4%CVE-2026-50224MEDIUMUnauthenticated IPv6 WAN Management ExposureEPSS 0.4%CVE-2025-12738LOWEnumeration of restricted property valueEPSS 0.4%CVE-2023-42829MEDIUMThe issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7.9, macOS EPSS 0.4%CVE-2022-48516—Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerabilityEPSS 0.4%CVE-2026-34088LOWRecentChanges entries expose suppressed content via generated log page htmlEPSS 0.4%CVE-2026-8825MEDIUMElementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST APIEPSS 0.4%