Fallos del tipo CWE-200

4979 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2021-21364MEDIUMGenerated Code Contains Local Information Disclosure VulnerabilityEPSS 0.3%CVE-2022-0553MEDIUMPossible to retrieve uncrypted firmware imageEPSS 0.3%CVE-2025-20379LOWRisky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk EnterpriseEPSS 0.3%CVE-2025-46720LOWKeystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fieldsEPSS 0.3%CVE-2026-70974MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2022-41926LOWNextcloud Talk Android broadcast incorrect permission handlingEPSS 0.3%CVE-2026-86441LOWMISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation DataEPSS 0.3%CVE-2025-11794MEDIUMPassword hash and MFA secret returned in user email verification endpointEPSS 0.3%CVE-2025-12540MEDIUMShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data ExposureEPSS 0.3%CVE-2026-18887MEDIUMIBM i is Affected By Sensitive Information Exposure Vulnerability in PASE []EPSS 0.3%CVE-2026-100668HIGHGrav before 2.0.25 Sandbox Escape via array FilterEPSS 0.3%CVE-2023-24012HIGHData Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Open DDSEPSS 0.3%CVE-2025-24217MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15EPSS 0.3%CVE-2022-23546MEDIUMDiscourse vulnerable to private topic leak via email#send_digestEPSS 0.3%CVE-2025-8515LOWIntelbras InControl JSON Endpoint operador information disclosureEPSS 0.3%CVE-2026-55608MEDIUMn8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP modeEPSS 0.3%CVE-2024-48011LOWDell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A loEPSS 0.3%CVE-2026-81348LOWMy Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and SitemapEPSS 0.3%CVE-2026-86407LOWUser Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membership Thank You PageEPSS 0.3%CVE-2026-86446LOWLearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST EndpointEPSS 0.3%