Fallos del tipo CWE-200

4898 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-21673MEDIUMOAuth Identity Token exposure in GrafanaEPSS 2.0%CVE-2021-41301CRITICALECOA BAS controller - Exposure of Sensitive Information to an Unauthorized ActorEPSS 2.0%CVE-2026-57219HIGHRabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurationsEPSS 2.0%CVE-2018-3831—Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured viEPSS 2.0%CVE-2025-22828MEDIUMApache CloudStack: Unauthorised access to annotationsEPSS 2.0%CVE-2019-1976HIGHCisco Industrial Network Director Configuration Data Information Disclosure VulnerabilityEPSS 2.0%CVE-2021-39200MEDIUMInformation Disclosure in wp_die() via JSONP in wordpressEPSS 2.0%CVE-2023-37379—Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" featureEPSS 2.0%CVE-2020-12802—remote graphics contained in docx format retrieved in 'stealth mode'EPSS 1.9%CVE-2019-11064—A vulnerability of remote credential disclosure was discovered in Advan VD-1EPSS 1.9%CVE-2022-26869CRITICALDell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentialEPSS 1.9%CVE-2021-41767—Private tunnel identifier may be included in the non-private details of active connectionsEPSS 1.9%CVE-2017-12169—It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remoteEPSS 1.9%CVE-2022-27949HIGHApache Airflow prior to 2.3.1 may include sensitive values in rendered templateEPSS 1.9%CVE-2019-0040MEDIUMJunos OS: Specially crafted packets sent to port 111 on any interface triggers responses from the management interfaceEPSS 1.9%CVE-2022-31090HIGHCURLOPT_HTTPAUTH option not cleared on change of origin in GuzzleEPSS 1.9%CVE-2022-31043HIGHFix failure to strip Authorization header on HTTP downgrade in GuzzleEPSS 1.9%CVE-2022-31042HIGHFailure to strip the Cookie header on change in host or HTTP downgrade in GuzzleEPSS 1.9%CVE-2019-5463—An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. ThiEPSS 1.9%CVE-2024-30569HIGHAn information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authenticaEPSS 1.9%