Fallos del tipo CWE-200

4975 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-36759HIGHSensitive Information Disclosure in SolaX CloudEPSS 0.3%CVE-2026-76041MEDIUMInformation leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crEPSS 0.3%CVE-2026-97179MEDIUMO2OA Cipher Connection CipherConnectionAction.java list information disclosureEPSS 0.3%CVE-2026-63645HIGHOpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL database credentialsEPSS 0.3%CVE-2025-58581MEDIUMInformation Disclosure Through Stacktrace-/MQTT/Config/changeAllEPSS 0.3%CVE-2024-39287MEDIUMDorsett Controls InfoScan Exposure of Sensitive Information To An Unauthorized ActorEPSS 0.3%CVE-2018-0368—A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive informatEPSS 0.3%CVE-2026-94611HIGHauthentik: Stored credentials are readable with view permission aloneEPSS 0.3%CVE-2025-4281MEDIUMShenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclosureEPSS 0.3%CVE-2024-43801MEDIUMPrivilege escalation to admin from a low-privileged user via SVG upload in JellyfinEPSS 0.3%CVE-2025-12408MEDIUMEvents Manager <= 7.2.2.2 - Unauthenticated Information ExposureEPSS 0.3%CVE-2023-7320MEDIUMWooCommerce <= 7.8.2 - Sensitive Information ExposureEPSS 0.3%CVE-2025-9139MEDIUMScada-LTS WatchListDwr.init.dwr information disclosureEPSS 0.3%CVE-2025-3628MEDIUMMoodle: moodle assignment submission search leaks anonymous student identitiesEPSS 0.3%CVE-2026-12120MEDIUMFireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' ParameterEPSS 0.3%CVE-2025-15033MEDIUMWooCommerce - Subscriber/Customer+ Order Data DisclosureEPSS 0.3%CVE-2026-58510MEDIUMGHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateEPSS 0.3%CVE-2026-55664MEDIUMGrist: Insufficient access control in the /forms endpoint exposes table metadataEPSS 0.3%CVE-2025-15381HIGHUnauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflowEPSS 0.3%CVE-2025-9240MEDIUMelunez eladmin info information disclosureEPSS 0.3%