Fallos del tipo CWE-200

4979 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-10051MEDIUMIn Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the EPSS 0.3%CVE-2025-12784MEDIUMCertain HP LaserJet Pro Printers – Potential Information DisclosureEPSS 0.3%CVE-2025-54345HIGHAn issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Information is exposed to an EPSS 0.3%CVE-2020-13179—Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in EPSS 0.3%CVE-2024-37180MEDIUM[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.3%CVE-2025-54323HIGHAn issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and EPSS 0.3%CVE-2025-63662HIGHInsecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive iEPSS 0.3%CVE-2026-32094MEDIUMShescape escape() leaves bracket glob expansion active on Bash, BusyBox, and DashEPSS 0.3%CVE-2024-7060LOWExposure of Sensitive Information to an Unauthorized Actor in GitLabEPSS 0.3%CVE-2022-22216MEDIUMJunos OS: PTX Series and QFX10000 Series: 'Etherleak' memory disclosure in Ethernet padding dataEPSS 0.3%CVE-2023-46741MEDIUMCubeFS leaks magic secret key when starting Blobstore access serviceEPSS 0.3%CVE-2026-13719MEDIUMAlert rules in restricted folders disclosed via the alert rules list APIEPSS 0.3%CVE-2024-38290MEDIUMIn XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.EPSS 0.3%CVE-2020-1987LOWGlobal Protect Agent: VPN cookie local information disclosureEPSS 0.3%CVE-2026-76256MEDIUMInformation Exposure through REST API Endpoints in Splunk Secure GatewayEPSS 0.3%CVE-2026-3433MEDIUMMattermost fails to scope role_updated websocket events to authorized team and channel membersEPSS 0.3%CVE-2026-10569MEDIUMIBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information VulnerabilityEPSS 0.3%CVE-2024-44336MEDIUMAn issue in AnkiDroid Android Application v2.17.6 allows attackers to retrieve internal files from the /data/data/com.ichi2.anki/ directory EPSS 0.3%CVE-2026-3636MEDIUMSanitize team member data returned by APIEPSS 0.3%CVE-2026-87035MEDIUMTanium addressed an information disclosure vulnerability in Comply.EPSS 0.3%