Fallos del tipo CWE-200

4975 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-6398MEDIUMAn information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a cuEPSS 0.3%CVE-2025-23215CRITICALPMD Designer's release key passphrase (GPG) available on Maven Central in cleartextEPSS 0.3%CVE-2026-84990HIGHntopng: Missing Authorization on System Configuration Backup Download and ListingEPSS 0.3%CVE-2025-6600MEDIUMGitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search APIEPSS 0.3%CVE-2026-67322HIGHGitPython before 3.1.52 Environment Variable Exfiltration via clone_fromEPSS 0.3%CVE-2026-56244HIGHCapgo - Webhook Signing Secret Disclosure via Non-Admin API KeyEPSS 0.3%CVE-2026-5375LOWrunZero Platform API credential information leakEPSS 0.3%CVE-2024-12538MEDIUMDuplicate Post, Page and Any Custom Post <= 3.5.5 - Authenticated (Contributor+) Post Disclosure via Post DuplicationEPSS 0.3%CVE-2026-100622HIGHcapgo.app through 12.129.0 Cache Restoration of Deleted BundlesEPSS 0.3%CVE-2024-41694MEDIUMCybonet – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2025-12426MEDIUMQuiz Maker <= 6.7.0.80 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-41659LOWAdmidio: Hidden Profile Field Values Leaked via Blind Search Oracle in Member AssignmentEPSS 0.3%CVE-2021-3602—An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds EPSS 0.3%CVE-2025-68718MEDIUMKAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root credentials (root:1234567EPSS 0.3%CVE-2025-24270MEDIUMThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4EPSS 0.3%CVE-2024-30135LOWSensitive Information Disclosure vulnerability affects DRYiCE AEX v10EPSS 0.3%CVE-2026-86767MEDIUMSnipe-IT before 8.7.0 Cross-Company Read via requested-assetsEPSS 0.3%CVE-2025-27980MEDIUMcashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.EPSS 0.3%CVE-2025-5266MEDIUMScript element events leaked cross-origin resource statusEPSS 0.3%CVE-2025-61220HIGHThe incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other users and gain unauEPSS 0.3%