Fallos del tipo CWE-200

4979 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-30454MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS SonEPSS 0.3%CVE-2025-3031MEDIUMJIT optimization bug with different stack slot sizesEPSS 0.3%CVE-2026-83354MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.EPSS 0.3%CVE-2026-55188HIGHRustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentialsEPSS 0.3%CVE-2018-0106—A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access EPSS 0.3%CVE-2026-79246MEDIUMInformation leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a craEPSS 0.3%CVE-2024-52032MEDIUMPrivate channel names leaking when Elasticsearch is enabledEPSS 0.3%CVE-2024-36118LOWUnauthorized viewing of workspace test cases in MeterSphereEPSS 0.3%CVE-2024-34029MEDIUMAD/LDAP Group Members LeakEPSS 0.3%CVE-2026-79122MEDIUMInformation leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted netEPSS 0.3%CVE-2023-47616LOWA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8EPSS 0.3%CVE-2025-4593MEDIUMWP Register Profile With Shortcode <= 3.6.2 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.3%CVE-2025-24089MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumeEPSS 0.3%CVE-2025-13758LOWExposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.EPSS 0.3%CVE-2025-14075MEDIUMWP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' ParameterEPSS 0.3%CVE-2026-1407LOWBeetel 777VR1 UART information disclosureEPSS 0.3%CVE-2026-14226MEDIUMEasy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure via REST Appointments ListingEPSS 0.3%CVE-2026-85349MEDIUMFluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOREPSS 0.3%CVE-2026-63240MEDIUMInformation disclosure vulnerabilityEPSS 0.3%CVE-2026-22604MEDIUMOpenProject is vulnerable to user enumeration via the change password functionEPSS 0.3%