Fallos del tipo CWE-200

4909 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2020-36723MEDIUMListingPro - WordPress Directory & Listing Theme < 2.6.1 - Sensitive Information DisclosureEPSS 1.6%CVE-1999-0059HIGHIRIX fam service allows an attacker to obtain a list of all files on the server.EPSS 1.6%CVE-2018-16870—It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLSEPSS 1.6%CVE-2020-1757HIGHA flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to unEPSS 1.6%CVE-2021-21564CRITICALDell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may pEPSS 1.6%CVE-2003-20001MEDIUMAn issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an eEPSS 1.6%CVE-2025-25037CRITICALAquatronica Controller System Complete Information DisclosureEPSS 1.6%CVE-2019-5470—An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could resulEPSS 1.6%CVE-2026-30928HIGHGlances Exposes Unauthenticated Configuration SecretsEPSS 1.6%CVE-2018-12130MEDIUMMicroarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authEPSS 1.6%CVE-2019-12704MEDIUMCisco SPA100 Series Analog Telephone Adapters Web-Based Management Interface File Disclosure VulnerabilityEPSS 1.6%CVE-2023-50298HIGHApache Solr: Solr can expose ZooKeeper credentials via Streaming ExpressionsEPSS 1.6%CVE-2021-4076—A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.EPSS 1.6%CVE-2020-6993—In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, an attacker can gain access to senEPSS 1.6%CVE-2018-0140—A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authEPSS 1.6%CVE-2021-32028—A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database EPSS 1.6%CVE-2023-42663—Apache Airflow: Bypass permission verification to view task instances of other dagsEPSS 1.6%CVE-2021-21360MEDIUMExposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetupEPSS 1.5%CVE-2022-40629HIGHSensitive Information Disclosure Vulnerability in Tacitine FirewallEPSS 1.5%CVE-2021-41120HIGHUnauthorized access to Credit card form in sylius/paypal-pluginEPSS 1.5%