Fallos del tipo CWE-200

4974 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-64761HIGHA privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able toEPSS 0.3%CVE-2026-49463MEDIUMNL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-librariesEPSS 0.3%CVE-2026-44431HIGHurllib3: Sensitive headers forwarded across origins in proxied low-level redirectsEPSS 0.3%CVE-2026-88059MEDIUMAngular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`EPSS 0.3%CVE-2026-64778MEDIUMThe issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26EPSS 0.3%CVE-2026-62286MEDIUMDozzle label filters do not restrict container event and statistics streamsEPSS 0.3%CVE-2024-23207MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 1EPSS 0.3%CVE-2026-100418MEDIUMFlame through 2.4.0 Information Exposure via GET /api/configEPSS 0.3%CVE-2023-24011HIGHData Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Cyclone DDSEPSS 0.3%CVE-2026-91766MEDIUMCross-origin credential leak in HTTP stream wrapper redirectsEPSS 0.3%CVE-2025-5064MEDIUMInappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin EPSS 0.3%CVE-2023-24010HIGHData Distribution Service (DDS) Chain of Trust (CoT) violation in Fast DDSEPSS 0.3%CVE-2026-46830MEDIUMVulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitablEPSS 0.3%CVE-2026-60394MEDIUMVulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.2EPSS 0.3%CVE-2026-60260MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2026-60156MEDIUMVulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulneraEPSS 0.3%CVE-2026-71087MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.3%CVE-2026-46841MEDIUMVulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitableEPSS 0.3%CVE-2026-60283MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2026-34273MEDIUMVulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily exploitable vulnerabEPSS 0.3%