Fallos del tipo CWE-200

4962 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-2228MEDIUMResponsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2020-1739LOWA flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svEPSS 0.4%CVE-2025-54468MEDIUMRancher sends sensitive information to external services through the `/meta/proxy` endpointEPSS 0.4%CVE-2026-34600MEDIUMJoplin Server delta API returns note content after share access is revokedEPSS 0.4%CVE-2026-55496MEDIUMCloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicateEPSS 0.4%CVE-2025-58589LOWInformation Disclosure Through StacktraceEPSS 0.4%CVE-2025-59454MEDIUMApache CloudStack: Lack of user permission validation leading to data leak for few APIsEPSS 0.4%CVE-2026-9183MEDIUM24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Information via Block Editor Script LocalizationEPSS 0.4%CVE-2025-39204HIGHA vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, sEPSS 0.4%CVE-2025-8852MEDIUMWuKongOpenSource WukongCRM API Response upload information exposureEPSS 0.4%CVE-2026-41183MEDIUMFreeScout allows non-folder conversation queries to disclose assigned-only hidden conversationsEPSS 0.4%CVE-2023-43995MEDIUMAn issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tEPSS 0.4%CVE-2023-43997MEDIUMAn issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channelEPSS 0.4%CVE-2023-43992MEDIUMAn issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acceEPSS 0.4%CVE-2026-45739LOWStrawberry GraphQL: Default GraphiQL may expose HTTP headers in URLsEPSS 0.4%CVE-2023-43994MEDIUMAn issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel aEPSS 0.4%CVE-2026-61782HIGH@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build MetadataEPSS 0.4%CVE-2023-5160MEDIUMFull name disclosure via team top membership with Show Full Name option disabledEPSS 0.4%CVE-2025-13526HIGHOneClick Chat to Order <= 1.0.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2024-12329MEDIUMEssential Real Estate <= 5.1.6 - Missing Authorization to Authenticated (Contributor+) Information ExposureEPSS 0.4%