Fallos del tipo CWE-200

4974 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-56526HIGHAn issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a SEPSS 0.4%CVE-2023-50872HIGHThe API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial informationEPSS 0.4%CVE-2025-7572MEDIUMLB-LINK BL-WR9000 lighttpd.cgi bs_GetHostInfo information disclosureEPSS 0.4%CVE-2024-56197LOWUsers can see other user's tagged PMs in DiscourseEPSS 0.4%CVE-2023-40723HIGHAn exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and EPSS 0.4%CVE-2026-47263MEDIUMDiscourse: Prevent webhook payload disclosure on event redeliveryEPSS 0.4%CVE-2026-40908MEDIUMWWBN AVideo has an Unauthenticated Information Disclosure via git.json.php that Exposes Developer Emails and Deployed VersionEPSS 0.4%CVE-2026-35413MEDIUMDirectus GraphQL Schema SDL Disclosure SettingEPSS 0.4%CVE-2025-0318MEDIUMUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information ExposureEPSS 0.4%CVE-2023-48714MEDIUMRecord titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleterEPSS 0.4%CVE-2024-5202HIGHDimensions RM - Arbitrary File ReadEPSS 0.4%CVE-2026-71849LOWHono: Proxy Helper does not remove response headers listed in the `Connection` headerEPSS 0.4%CVE-2026-73055MEDIUMShescape before 2.1.15 and 3.0.2 Home Directory Disclosure via BusyBoxEPSS 0.4%CVE-2025-1063MEDIUMClassified Listing – Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings ExposureEPSS 0.4%CVE-2026-28976HIGHAn information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root prEPSS 0.4%CVE-2023-42884MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.EPSS 0.4%CVE-2024-13451MEDIUMContact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2025-29486MEDIUMlibming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.EPSS 0.4%CVE-2024-34003MEDIUMmoodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_workshop backupEPSS 0.4%CVE-2026-32099MEDIUMDiscourse prevents hidden profile data leak via user oneboxEPSS 0.4%