Fallos del tipo CWE-200

4991 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-50184MEDIUMAngular: Request Credential & Cache Policy Stripping in Angular Service WorkerEPSS 0.2%CVE-2026-101265LOWIntelbras TIP 125i Básico sensitive information in sourceEPSS 0.2%CVE-2021-20260—A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with EPSS 0.2%CVE-2023-4177LOWEmpowerID Multi-Factor Authentication Code information disclosureEPSS 0.2%CVE-2026-16983MEDIUMGutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST APIEPSS 0.2%CVE-2022-25826LOWInformation Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of coEPSS 0.2%CVE-2025-43391MEDIUMA privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7EPSS 0.2%CVE-2022-25827LOWInformation Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information ofEPSS 0.2%CVE-2026-57449HIGHActual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub TokenEPSS 0.2%CVE-2026-2317MEDIUMInappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a EPSS 0.2%CVE-2022-25829LOWInformation Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information oEPSS 0.2%CVE-2026-90441HIGHFireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant BEPSS 0.2%CVE-2022-25823LOWInformation Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in lEPSS 0.2%CVE-2022-25830LOWInformation Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information oEPSS 0.2%CVE-2026-100851HIGHAzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profileEPSS 0.2%CVE-2022-25828LOWInformation Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information ofEPSS 0.2%CVE-2026-88929MEDIUMSale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product DisclosureEPSS 0.2%CVE-2026-17517MEDIUMContent Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Status FilterEPSS 0.2%CVE-2026-90988MEDIUMRequest a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenumEPSS 0.2%CVE-2026-92995MEDIUMVerge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_fileEPSS 0.2%