Fallos del tipo CWE-200

4992 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-65104HIGHFirebird: Information leak vulnerability in firebird3 client when used with newer serverEPSS 0.2%CVE-2024-54550MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15EPSS 0.2%CVE-2025-31256MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a usEPSS 0.2%CVE-2026-49988MEDIUMRepomix: attach_packed_output can bypass file-read secret scanning for supported local filesEPSS 0.2%CVE-2022-42442LOWIBM Robotic Process Automation for Cloud Pak information disclosureEPSS 0.2%CVE-2024-29720MEDIUMAn issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt componentEPSS 0.2%CVE-2026-22051LOWStorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerabiliEPSS 0.2%CVE-2025-20030LOWExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.2%CVE-2025-11998MEDIUMHP Card Readers (B Models) – Potential Information DisclosureEPSS 0.2%CVE-2022-20591MEDIUMIn ppmpu_set of ppmpu.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information dEPSS 0.2%CVE-2024-45450MEDIUMPermission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.2%CVE-2024-2371MEDIUMInformation exposure vulnerability in Korenix JetI/O 6550EPSS 0.2%CVE-2023-38300MEDIUMA certain software build for the Orbic Maui device (Orbic/RC545L/RC545L:10/ORB545L_V1.4.2_BVZPP/230106:user/release-keys) leaks the IMEI andEPSS 0.2%CVE-2026-16592LOWWP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via ShortcodesEPSS 0.2%CVE-2026-47395MEDIUMPraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model contextEPSS 0.2%CVE-2025-31231MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitEPSS 0.2%CVE-2022-46646LOWExposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enaEPSS 0.2%CVE-2022-34314MEDIUM IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force ID: 229450. EPSS 0.2%CVE-2025-57839MEDIUMPhoto module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentialityEPSS 0.2%CVE-2025-57838MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confideEPSS 0.2%