Fallos del tipo CWE-200

4976 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-24244MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, mEPSS 0.3%CVE-2026-19435LOWCopy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password DisclosureEPSS 0.3%CVE-2026-100723MEDIUMvm2 before 3.12.2 Memory Disclosure via zlib Buffer PoolEPSS 0.3%CVE-2026-89008LOWBookit < 2.6.0.5 - Bookit Staff+ Appointment PII DisclosureEPSS 0.3%CVE-2026-59180LOWApprise forwards configured auth headers across cross-origin HTTP redirectsEPSS 0.3%CVE-2026-63432MEDIUMHorilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password Hashes and Server MetadataEPSS 0.3%CVE-2025-20270MEDIUMCisco Evolved Programmable Network Manager Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-101083MEDIUMPMWeb encryptionhelper.dll information disclosureEPSS 0.3%CVE-2026-20360HIGHCisco Nexus Dashboard Software Security Hardening Release September 2026 - Information Exposure & Insecure HandlingEPSS 0.3%CVE-2024-58256MEDIUMEnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.EPSS 0.3%CVE-2022-0851—There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subEPSS 0.3%CVE-2026-100241HIGHPrivate change tags exposed to anonymous users via revision-tags-change eventsEPSS 0.3%CVE-2026-60888MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.3%CVE-2023-43814LOWExposure of poll options and votes to unauthorized users in DiscourseEPSS 0.3%CVE-2025-11760MEDIUMeRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-7021MEDIUMSmythOS sre Connector Service utils.ts information disclosureEPSS 0.3%CVE-2026-62490MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2026-65758HIGHJoomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2EPSS 0.3%CVE-2025-26485MEDIUMA vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usaEPSS 0.3%CVE-2024-27731MEDIUMCross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file typeEPSS 0.3%