Fallos del tipo CWE-200

4989 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2021-4135—A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for theEPSS 0.2%CVE-2021-25403—Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) aEPSS 0.2%CVE-2026-20137LOWRisky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk EnterpriseEPSS 0.2%CVE-2021-25432—Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.EPSS 0.2%CVE-2026-60864MEDIUMVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.2%CVE-2026-77320MEDIUMTREK: Public trip share link ignores the `share_map` permission server-side (client-enforced authorization → itinerary/location disclosure)EPSS 0.2%CVE-2024-40842MEDIUMAn issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15. An app may be able to accEPSS 0.2%CVE-2022-36877LOWExposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in ChinaEPSS 0.2%CVE-2025-46388MEDIUMCWE-200 Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.2%CVE-2025-10281MEDIUMInsecure URL Handling in git_clone Leading to Leaked API KeyEPSS 0.2%CVE-2021-32002MEDIUMSiteManager troubleshooter allows access without authentication from local networkEPSS 0.2%CVE-2023-23511—The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, iOS 16.3 and iPadOSEPSS 0.2%CVE-2024-44129MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Ventura 13.7. An app may be able to leak sensitEPSS 0.2%CVE-2023-29116MEDIUMPHP Information Disclosure in Enel X JuiceBoxEPSS 0.2%CVE-2025-10282MEDIUMGitLab Domain Confusion in gitlab Leaks API KeyEPSS 0.2%CVE-2026-87521LOWInformation leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtEPSS 0.2%CVE-2026-87451LOWInformation leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to EPSS 0.2%CVE-2025-8866MEDIUMYugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attackEPSS 0.2%CVE-2025-43460MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locEPSS 0.2%CVE-2026-79034LOWInformation leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak EPSS 0.2%