Fallos del tipo CWE-200

4909 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2018-12126MEDIUMMicroarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an auEPSS 1.5%CVE-2025-24011MEDIUMUmbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response CodesEPSS 1.5%CVE-2021-32029—A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read EPSS 1.5%CVE-2024-10916MEDIUMD-Link DNS-320/DNS-320LW/DNS-325/DNS-340L HTTP GET Request info.xml information disclosureEPSS 1.5%CVE-2023-1387MEDIUMGrafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to searcEPSS 1.5%CVE-2023-24881MEDIUMMicrosoft Teams Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-27844LOWWordPress WPvivid plugin <= 0.9.70 - Arbitrary File Read vulnerabilityEPSS 1.5%CVE-2008-3893MEDIUMMicrosoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear thisEPSS 1.5%CVE-2018-10852LOWThe UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone EPSS 1.5%CVE-2021-21336MEDIUMExposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManagerEPSS 1.5%CVE-2022-47184HIGHApache Traffic Server: The TRACE method can be use to disclose network informationEPSS 1.5%CVE-2023-33933HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.5%CVE-2018-0474MEDIUMCisco Unified Communications Manager Digest Credentials Disclosure VulnerabilityEPSS 1.5%CVE-2026-52815MEDIUMGogs: Unauthenticated Organization Teams Information Disclosure via APIEPSS 1.5%CVE-2018-13288MEDIUMInformation exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remoteEPSS 1.5%CVE-2018-13297MEDIUMInformation exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitEPSS 1.5%CVE-2018-0218—A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticateEPSS 1.5%CVE-2018-0207—A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticateEPSS 1.5%CVE-2017-11510—An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator usEPSS 1.5%CVE-2018-0187MEDIUMCisco Identity Services Engine Privileged Account Sensitive Information Disclosure VulnerabilityEPSS 1.5%