Fallos del tipo CWE-200

4979 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-22203MEDIUMwpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in PlaintextEPSS 0.3%CVE-2025-12147MEDIUMUnauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an objectEPSS 0.3%CVE-2026-15758MEDIUM3D FlipBook <= 1.16.20 - Unauthenticated Sensitive Information Exposure in 'id' ParameterEPSS 0.3%CVE-2025-65090MEDIUMXWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONServiceEPSS 0.3%CVE-2021-3798—A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObjEPSS 0.3%CVE-2026-55837MEDIUMdbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform TokensEPSS 0.3%CVE-2020-8316MEDIUMA vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the sysEPSS 0.3%CVE-2026-41079MEDIUMOpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated usersEPSS 0.3%CVE-2025-6745MEDIUMWoodMart <= 8.2.5 - Unauthenticated Post DisclosureEPSS 0.3%CVE-2025-12521MEDIUMAnalytify Pro <= 7.0.3 - Unauthenticated Information ExposureEPSS 0.3%CVE-2022-32858MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. An app may be able to leaEPSS 0.3%CVE-2026-62998MEDIUMREDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column EnumerationEPSS 0.3%CVE-2026-2128MEDIUMBreeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login CookieEPSS 0.3%CVE-2022-32877MEDIUMA configuration issue was addressed with additional restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Monterey 12.6. An app mayEPSS 0.3%CVE-2024-40850MEDIUMA file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macEPSS 0.3%CVE-2026-12392MEDIUMRPC secret disclosure via vendor data endpoint in Canonical MAASEPSS 0.3%CVE-2021-20259—A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attackeEPSS 0.3%CVE-2025-7368MEDIUMRehub <= 19.9.7 - Unauthenticated Password Protected Post DisclosureEPSS 0.3%CVE-2024-27814LOWThis issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device mEPSS 0.3%CVE-2024-12575MEDIUMPoll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information ExposureEPSS 0.3%