Fallos del tipo CWE-200

4992 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-32670HIGHExposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes to potentially identEPSS 0.2%CVE-2022-39859MEDIUMImplicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive information via impEPSS 0.2%CVE-2023-1055—A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificaEPSS 0.2%CVE-2024-8097MEDIUMSensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST levelEPSS 0.2%CVE-2024-20914LOWVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected EPSS 0.2%CVE-2024-22331MEDIUMIBM UrbanCode Deploy information disclosureEPSS 0.2%CVE-2022-34355MEDIUMIBM Jazz Foundation information disclosureEPSS 0.2%CVE-2026-100640HIGHSiYuan before v3.8.4 Clipboard Data Disclosure via IPCEPSS 0.2%CVE-2026-54605HIGHOAuth: Cross-origin token-request redirects can expose signed request metadataEPSS 0.2%CVE-2024-54009MEDIUMRemote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited EPSS 0.2%CVE-2025-46283MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. AnEPSS 0.2%CVE-2026-16302MEDIUMSpectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.2%CVE-2025-43523MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may beEPSS 0.2%CVE-2026-88013LOWrclone: http backend forwards custom/auth headers to a different host on redirectEPSS 0.2%CVE-2026-82841MEDIUMUpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration NoticeEPSS 0.2%CVE-2023-5920LOWLack Of Secure Keyboard Entry Protection in MacOS DesktopEPSS 0.2%CVE-2022-32931MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to EPSS 0.2%CVE-2024-3780HIGHInformation exposure vulnerability on Technicolor CGA2121EPSS 0.2%CVE-2026-40159MEDIUMPraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess ExecutionEPSS 0.2%CVE-2025-65104HIGHFirebird: Information leak vulnerability in firebird3 client when used with newer serverEPSS 0.2%