Fallos del tipo CWE-200

5018 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-28877MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOEPSS 0.2%CVE-2026-83279MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-83274MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-86878MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to access seEPSS 0.2%CVE-2022-38688MEDIUMIn telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2026-42283HIGHDevSpace UI Server WebSocket CheckOrigin does not validate sourceEPSS 0.1%CVE-2026-63278MEDIUMPackage URLs can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.1%CVE-2026-90811MEDIUMcosmicstack-labs mercury-agent Shell Permission Manifest permissions.ts PermissionManager.checkShellCommand information disclosureEPSS 0.1%CVE-2026-16398HIGHSite isolation issue in the Graphics componentEPSS 0.1%CVE-2026-90895HIGHMISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal InjectionEPSS 0.1%CVE-2026-84530LOWAn information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iEPSS 0.1%CVE-2025-20611MEDIUMExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.1%CVE-2024-39600MEDIUM[CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for WindowsEPSS 0.1%CVE-2025-8887MEDIUMIDOR in Usta Information Systems' Aybs InteraktifEPSS 0.1%CVE-2022-39904LOWExposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the NetEPSS 0.1%CVE-2026-82810MEDIUMextension.vn 2FA Authenticator Extension Background Service Worker chrome.runtime.onMessageExternal.addListener information disclosureEPSS 0.1%CVE-2026-79780MEDIUMrclone before v1.75.0 Credential Exposure via S3 RedirectEPSS 0.1%CVE-2026-60886HIGHVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2025-43201MEDIUMThis issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may be able to unexpecteEPSS 0.1%CVE-2026-47165MEDIUMImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication modelEPSS 0.1%