Fallos del tipo CWE-200

4991 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-6294LOWudn News App - Sensitive Information ExposureEPSS 0.2%CVE-2023-41987MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.EPSS 0.2%CVE-2024-52966LOWAn exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause informaEPSS 0.2%CVE-2023-40411MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive EPSS 0.2%CVE-2025-25209MEDIUMRhcl: sharedsecretref can be used to leak secrets severityEPSS 0.2%CVE-2024-54547MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app mEPSS 0.2%CVE-2024-56443MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2025-24142MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma EPSS 0.2%CVE-2022-1662—In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password EPSS 0.2%CVE-2026-96869MEDIUMInformation disclosure in the Networking componentEPSS 0.2%CVE-2026-53682MEDIUMPki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hostsEPSS 0.2%CVE-2026-101265LOWIntelbras TIP 125i Básico sensitive information in sourceEPSS 0.2%CVE-2026-67172LOWHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-16983MEDIUMGutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST APIEPSS 0.2%CVE-2021-20260—A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with EPSS 0.2%CVE-2023-4177LOWEmpowerID Multi-Factor Authentication Code information disclosureEPSS 0.2%CVE-2026-50184MEDIUMAngular: Request Credential & Cache Policy Stripping in Angular Service WorkerEPSS 0.2%CVE-2022-25829LOWInformation Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information oEPSS 0.2%CVE-2022-25827LOWInformation Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information ofEPSS 0.2%CVE-2026-100851HIGHAzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profileEPSS 0.2%