Fallos del tipo CWE-200

4959 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-5516MEDIUM Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing informatioEPSS 0.4%CVE-2024-40633MEDIUMCustomer data leak via adjustments API endpoint in SyliusEPSS 0.4%CVE-2024-22032HIGHRancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpecEPSS 0.4%CVE-2023-5515MEDIUM The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal sEPSS 0.4%CVE-2026-56729LOWZammad: Titles of knowledge base answers will be shown across all categories via the global searchEPSS 0.4%CVE-2023-38245MEDIUMAdobe Acrobat Reader DC ActiveX Control (AxAcroPDFLib.AxAcroPDF) src NTLMv2 SSO Hash Theft VulnerabilityEPSS 0.4%CVE-2023-31280MEDIUMExposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2025-26001HIGHTelesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.EPSS 0.4%CVE-2025-54380MEDIUMOpencast still publishes global system account credentialsEPSS 0.4%CVE-2026-60647HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2019-5641LOWRapid7 InsightVM Information Disclosure after LogoutEPSS 0.4%CVE-2024-13807HIGHXagio SEO <= 7.1.0.5 - Unauthenticated Sensitive Information Exposure via Unprotected Back-Up FilesEPSS 0.4%CVE-2024-31464MEDIUMXWiki Platform: Password hash might be leaked by diff once the xobject holding them is deletedEPSS 0.4%CVE-2024-11008MEDIUMMembers <= 3.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.4%CVE-2024-33753HIGHSection Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changedEPSS 0.4%CVE-2024-44820HIGHA sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/EPSS 0.4%CVE-2025-0525LOWIn affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could EPSS 0.4%CVE-2026-19300HIGHLangflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flowsEPSS 0.4%CVE-2025-5184MEDIUMSummer Pearl Group Vacation Rental Management Platform HTTP Response Header information disclosureEPSS 0.4%CVE-2023-21833MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is aEPSS 0.4%