Fallos del tipo CWE-200

4909 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-55875CRITICALhttp4k has a potential XXE (XML External Entity Injection) vulnerabilityEPSS 1.9%CVE-2023-39337—A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier tEPSS 1.9%CVE-2025-53624CRITICALdocusaurus-plugin-content-gists Exposes GitHub Personal Access TokenEPSS 1.9%CVE-2021-3426MEDIUMThere's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to starEPSS 1.9%CVE-2026-69806HIGH.NET Elevation of Privilege VulnerabilityEPSS 1.9%CVE-2019-10217MEDIUMA flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fieldsEPSS 1.9%CVE-2021-22892—An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be dEPSS 1.9%CVE-2024-8461MEDIUMD-Link DNS-320 Web Management Interface discovery.cgi information disclosureEPSS 1.9%CVE-2020-8481CRITICALABB Central Licensing System - Information disclosureEPSS 1.9%CVE-2019-15576—An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private syEPSS 1.9%CVE-2019-6574—A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions EPSS 1.8%CVE-2017-2606MEDIUMJenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that shouEPSS 1.8%CVE-2025-59214MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 1.8%CVE-2024-38020MEDIUMMicrosoft Outlook Spoofing VulnerabilityEPSS 1.8%CVE-2019-7305MEDIUMeXtplorer exposes /usr and /etc/extplorer over HTTPEPSS 1.8%CVE-2022-39258HIGHmailcow-dockerized critical information misrepresentation can lead to phishing attacks through Swagger UIEPSS 1.8%CVE-2019-13523—In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to EPSS 1.8%CVE-2017-16539MEDIUMThe DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackeEPSS 1.8%CVE-2021-24948—The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data DisclosureEPSS 1.8%CVE-2023-45131HIGHUnauthenticated access to new private chat messages in DiscourseEPSS 1.8%