Fallos del tipo CWE-200

4992 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-4040MEDIUMOpenClaw File Existence tools.exec.safeBins information exposureEPSS 0.2%CVE-2025-11645LOWTomofun Furbo Mobile App Authentication Token sensitive informationEPSS 0.2%CVE-2025-24884MEDIUMkube-audit-rest's example logging configuration could disclose secret values in the audit logEPSS 0.2%CVE-2024-54475LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma EPSS 0.2%CVE-2026-84359LOWInformation leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak EPSS 0.2%CVE-2023-28203MEDIUMThe issue was addressed with improved checks. This issue is fixed in Apple Music 4.2.0 for Android. An app may be able to access contacts.EPSS 0.2%CVE-2026-49449LOWJoplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on WindowsEPSS 0.2%CVE-2026-81870LOWOpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logsEPSS 0.2%CVE-2024-20920LOWVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. EasilEPSS 0.2%CVE-2025-55165HIGHAutocaliweb Exposure of Sensitive Information to an Unauthorized Actor in `config_sql.py`EPSS 0.2%CVE-2025-46820HIGHphpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifactEPSS 0.2%CVE-2026-79252MEDIUMInformation leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafteEPSS 0.2%CVE-2025-14553HIGHPassword Hash Leak Could Lead to Unauthorized Access on Tapo App via Local NetworkEPSS 0.2%CVE-2026-20141MEDIUMImproper Access Control in Splunk Monitoring Console AppEPSS 0.2%CVE-2026-55406MEDIUMBuffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in DerefEPSS 0.2%CVE-2026-13611MEDIUMKiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data DisclosureEPSS 0.2%CVE-2026-60413HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version EPSS 0.2%CVE-2023-1633MEDIUMInsecure barbican configuration file leaking credentialEPSS 0.2%CVE-2026-45536MEDIUMNetty: Unix-socket fd receive leaks descriptors when peer sends two at onceEPSS 0.2%CVE-2026-60414HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version EPSS 0.2%