Fallos del tipo CWE-200

4980 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-37909MEDIUMAruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The sceEPSS 0.3%CVE-2024-42208LOWHCL Connections is vulnerable to an information disclosure vulnerabilityEPSS 0.3%CVE-2026-78908MEDIUMInformation leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML EPSS 0.3%CVE-2026-15044MEDIUMTrustyai-service-operator: trustyai service operator: unauthenticated access to ai guardrails and orchestrator apisEPSS 0.3%CVE-2026-78895MEDIUMInformation leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML pEPSS 0.3%CVE-2025-26711MEDIUMThere is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized EPSS 0.3%CVE-2023-21067—Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/AEPSS 0.3%CVE-2026-78987MEDIUMInformation leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML EPSS 0.3%CVE-2021-25333LOWImproper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreEPSS 0.3%CVE-2025-24134MEDIUMAn information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3. An app may be able EPSS 0.3%CVE-2021-25332LOWImproper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscrEPSS 0.3%CVE-2025-40757MEDIUMA vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC SEPSS 0.3%CVE-2026-60371HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2024-1949LOWA race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized accEPSS 0.3%CVE-2021-25331LOWImproper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreEPSS 0.3%CVE-2023-21237MEDIUMIn applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading orEPSS 0.3%KEVCVE-2025-27387HIGHOPPO Clone Phone uses weak WPA passphrase as only means of securityEPSS 0.3%CVE-2022-32875MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, EPSS 0.3%CVE-2026-60589LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 0.3%CVE-2024-44685MEDIUMTitan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwordEPSS 0.3%