Fallos del tipo CWE-200

4909 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-36043MEDIUMOpen Management Infrastructure Information Disclosure VulnerabilityEPSS 1.4%CVE-2022-23952HIGHIn Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.EPSS 1.4%CVE-2021-32690MEDIUMRepository credentials passed to alternate domainEPSS 1.4%CVE-2022-0812—An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker EPSS 1.4%CVE-2021-31567MEDIUMWordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerabilityEPSS 1.4%CVE-2022-41876HIGHezplatform-graphql GraphQL queries can expose password hashesEPSS 1.4%CVE-2022-27241—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (AllEPSS 1.4%CVE-2019-15583—An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When anEPSS 1.4%CVE-2023-40511HIGHLG Simple Editor checkServer Authentication Bypass VulnerabilityEPSS 1.4%CVE-2023-40510HIGHLG Simple Editor getServerSetting Authentication Bypass VulnerabilityEPSS 1.4%CVE-2021-32747MEDIUMCustom variable protection and blacklists can be circumventedEPSS 1.4%CVE-2022-21712HIGHCookie and header exposure in twistedEPSS 1.4%CVE-2021-37629MEDIUMLack of ratelimit on Richdocuments OCS endpoint in nextcloudEPSS 1.4%CVE-2019-6852HIGHA CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium coEPSS 1.4%CVE-2022-24797MEDIUMExposure of Sensitive Information in PomeriumEPSS 1.4%CVE-2020-7510—A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtainEPSS 1.4%CVE-2024-42658HIGHAn issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's paraEPSS 1.4%CVE-2021-22905—Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being perforEPSS 1.4%CVE-2020-11009MEDIUMIDOR can reveal execution data and logs to unauthorized user in RundeckEPSS 1.4%CVE-2025-26263MEDIUMGeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure dEPSS 1.4%