Fallos del tipo CWE-200

4992 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-33919HIGHDell GeoDrive, versions 2.1 - 2.2, contains an information disclosure vulnerability in GUI. An authenticated non-admin user could potentiallEPSS 0.2%CVE-2026-77321MEDIUMTREK MCP trip summary bypasses delegated OAuth read scopesEPSS 0.2%CVE-2026-0747LOWExposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025EPSS 0.2%CVE-2021-3923LOWA flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel sEPSS 0.2%CVE-2022-43901MEDIUMIBM WebSphere Automation for IBM Cloud Pak for Watson AIOps information disclosureEPSS 0.2%CVE-2025-8448LOWCWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive cEPSS 0.2%CVE-2023-31413MEDIUMFilebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization hEPSS 0.2%CVE-2025-56463MEDIUMMercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.EPSS 0.2%CVE-2021-21590MEDIUMDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local maliciouEPSS 0.2%CVE-2021-21591MEDIUMDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local maliciouEPSS 0.2%CVE-2026-53467MEDIUMImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchangedEPSS 0.2%CVE-2023-40368MEDIUMIBM Storage Protect information disclosureEPSS 0.2%CVE-2026-97317MEDIUMGiveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway PageEPSS 0.2%CVE-2025-64703MEDIUMMaxKB has Information Leak in sandboxEPSS 0.2%CVE-2022-48610MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2EPSS 0.2%CVE-2025-29316MEDIUMAn issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive iEPSS 0.2%CVE-2023-46669MEDIUMElastic Agent / Elastic Endpoint Security local API key disclosureEPSS 0.2%CVE-2026-92070MEDIUMInformation disclosure in the Networking componentEPSS 0.2%CVE-2026-15075HIGHIn Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates alEPSS 0.2%CVE-2024-54475LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma EPSS 0.2%