Fallos del tipo CWE-200

4975 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-33422LOWDiscourse exposes ip_address of flagged userEPSS 0.3%CVE-2026-58036LOWUsers API leaks whether privileged users have their user groups disabled for lack of 2FAEPSS 0.3%CVE-2025-46676LOWDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 releaseEPSS 0.3%CVE-2025-55265MEDIUMHCL Aftermarket DPC is affected by File DiscoveryEPSS 0.3%CVE-2026-87541MEDIUMInformation leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process toEPSS 0.3%CVE-2023-41881LOWDeleting a collaboration should also delete linked resourcesEPSS 0.3%CVE-2026-50019MEDIUMyt-dlp: File Downloader cookie leak with curlEPSS 0.3%CVE-2026-44785MEDIUMDiscourse: Hidden reply-to post raw can be disclosed through AI explain promptsEPSS 0.3%CVE-2026-44782MEDIUMDiscourse: GroupPostSerializer leaks hidden full names through reaction post associationEPSS 0.3%CVE-2026-44780MEDIUMDiscourse: Category queue reviewers can read raw incoming emails from queued postsEPSS 0.3%CVE-2025-53047MEDIUMVulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21EPSS 0.3%CVE-2026-14004MEDIUMInappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafteEPSS 0.3%CVE-2026-87477MEDIUMInformation leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML EPSS 0.3%CVE-2026-79291MEDIUMInformation leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTMLEPSS 0.3%CVE-2026-13810MEDIUMInappropriate implementation in Input in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensiEPSS 0.3%CVE-2026-42873NONEWeGIA: Error Handling Upload DocDependenteEPSS 0.3%CVE-2026-79271MEDIUMInformation leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive EPSS 0.3%CVE-2026-87490MEDIUMInformation leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information EPSS 0.3%CVE-2026-79125MEDIUMInformation leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML EPSS 0.3%CVE-2026-87593MEDIUMInformation leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted EPSS 0.3%