Fallos del tipo CWE-200

4958 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-33300MEDIUMDiscourse: Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpointEPSS 0.4%CVE-2026-83352HIGHVulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 1EPSS 0.4%CVE-2024-34696MEDIUM GeoServer's Server Status shows sensitive environmental variables and Java propertiesEPSS 0.4%CVE-2026-83425HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.4%CVE-2026-55792MEDIUMCraft CMS: Sensitive File Disclosure / Server-Side File ReadEPSS 0.4%CVE-2026-83302HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). The supported version that is affEPSS 0.4%CVE-2026-32143MEDIUMDiscourse: Admin-only report can be exported by moderatorsEPSS 0.4%CVE-2026-42220MEDIUMnginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollbackEPSS 0.4%CVE-2026-83259HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-61746MEDIUMInvenTree: Plugin-settings GET endpoints are readable without authenticationEPSS 0.4%CVE-2025-3831HIGHExposed SFTP serverEPSS 0.4%CVE-2023-26441MEDIUMCacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An atEPSS 0.4%CVE-2024-31219MEDIUMDiscourse-reactions' reaction data and public topic whisper content exposed on reactions given user activity pageEPSS 0.4%CVE-2026-83238HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-83237HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-86064HIGHKlever-Go: /log controls global node loggingEPSS 0.4%CVE-2026-83300HIGHVulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 1EPSS 0.4%CVE-2024-10548MEDIUMWP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST APIEPSS 0.4%CVE-2026-62559MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.4%CVE-2025-23203MEDIUMIcinga has rest API endpoints accessible to restricted usersEPSS 0.4%