Fallos del tipo CWE-200

4909 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2020-8210—Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile SEPSS 1.5%CVE-2025-6082MEDIUMBirth Chart Compatibility <= 2.0 - Unauthenticated Full Path ExposureEPSS 1.5%CVE-2023-38344—An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP actioEPSS 1.5%CVE-2018-10857MEDIUMgit-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annEPSS 1.5%CVE-2016-9159MEDIUMA vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPEPSS 1.5%CVE-2026-2025HIGHMail Mint < 1.19.5 - Unauthenticated Emails DisclosureEPSS 1.5%CVE-2020-35518—When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be usedEPSS 1.5%CVE-2019-13410—TOPMeeting version before version 8.8 (2019/08/19) allows an attacker to obtain sensitive informationEPSS 1.5%CVE-2023-35005—Apache Airflow: Information disclosure on configuration viewEPSS 1.5%CVE-2025-29805HIGHOutlook for Android Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-31091HIGHChange in port should be considered a change in origin in GuzzleEPSS 1.5%CVE-2017-12224—A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remoEPSS 1.5%CVE-2022-34708MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.5%CVE-2026-13153HIGHEssential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products EndpointEPSS 1.5%CVE-2022-34710MEDIUMWindows Defender Credential Guard Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-34712MEDIUMWindows Defender Credential Guard Information Disclosure VulnerabilityEPSS 1.5%CVE-2021-3714—A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via EPSS 1.5%CVE-2018-16849LOWA flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presenceEPSS 1.5%CVE-2019-1010299—The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of unEPSS 1.5%CVE-2018-12126MEDIUMMicroarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an auEPSS 1.5%