Fallos del tipo CWE-200

4909 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2019-10195MEDIUMA flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way thEPSS 1.8%CVE-2022-43684CRITICALACL bypass in Reporting functionalityEPSS 1.8%CVE-2021-20313—A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is poEPSS 1.8%CVE-2017-2609MEDIUMjenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autoEPSS 1.8%CVE-2018-1052—Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read aEPSS 1.8%CVE-2021-41082HIGHPrivate message title and participating users leaked in discourseEPSS 1.8%CVE-2025-26667MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.8%CVE-2024-21136HIGHVulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are aEPSS 1.8%CVE-2020-11021MEDIUMHTTP request which redirect to another hostname do not strip authorization header in Actions Http-ClientEPSS 1.8%CVE-2019-10223MEDIUMA security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 releasEPSS 1.8%CVE-2020-15099HIGHExposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMSEPSS 1.8%CVE-2019-10156MEDIUMA flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of EPSS 1.8%CVE-2016-7061LOWAn information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuEPSS 1.8%CVE-2016-6542—The MAC address/device tracking ID of an iTrack Easy can be obtained within range of the deviceEPSS 1.7%CVE-2026-32596HIGHGlances exposes the REST API without authenticationEPSS 1.7%CVE-2025-32395MEDIUMVite has an `server.fs.deny` bypass with an invalid `request-target`EPSS 1.7%CVE-2021-27434—Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework verEPSS 1.7%CVE-2018-0105—A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitiEPSS 1.7%CVE-2017-6614—A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authentiEPSS 1.7%CVE-2018-14803—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that couldEPSS 1.7%