Fallos del tipo CWE-200

4988 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2021-4023—A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper caEPSS 0.2%CVE-2026-76089HIGHFormie: Missing authorization on sent notification resend modal exposes submission PIIEPSS 0.2%CVE-2025-54966MEDIUMAn issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return sensitive informationEPSS 0.2%CVE-2025-52631LOWHCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability.EPSS 0.2%CVE-2025-52634LOWHCL AION is susceptible to Spring Boot Actuator Endpoints ExposedEPSS 0.2%CVE-2025-52630LOWHCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerabilityEPSS 0.2%CVE-2025-20624MEDIUMExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.2%CVE-2026-101092MEDIUMSiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImagesEPSS 0.2%CVE-2026-100719HIGHFroxlor before 2.3.12 Credential Disclosure via DirProtections APIEPSS 0.2%CVE-2025-59019MEDIUMInformation Disclosure via CSV DownloadEPSS 0.2%CVE-2025-61885MEDIUMVulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server). The supported verEPSS 0.2%CVE-2025-4426MEDIUMSetupAutomationSmm : SMRAM memory contents leak / information disclosure vulnerability in SMM moduleEPSS 0.2%CVE-2021-21536MEDIUMDell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vuEPSS 0.2%CVE-2026-79207MEDIUMInformation leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information viaEPSS 0.2%CVE-2021-21537MEDIUMDell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vuEPSS 0.2%CVE-2026-67104MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-0340MEDIUMKernel: information disclosure in vhost/vhost.c:vhost_new_msg()EPSS 0.2%CVE-2026-78981MEDIUMInformation leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive informEPSS 0.2%CVE-2026-2244HIGHSensitive Data Exposure in Google Cloud Vertex AI WorkbenchEPSS 0.2%CVE-2025-11639MEDIUMTomofun Furbo 360/Furbo Mini Debug Log S3 Bucket collect_logs.sh sensitive informationEPSS 0.2%