Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2017-15139MEDIUMA vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume EPSS 1.2%CVE-2021-23858HIGHInformation disclosureEPSS 1.2%CVE-2022-34704MEDIUMWindows Defender Credential Guard Information Disclosure VulnerabilityEPSS 1.2%CVE-2023-43791CRITICALLabel Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session TokensEPSS 1.2%CVE-2022-24865MEDIUMImproper access control in humhubEPSS 1.2%CVE-2017-12365—A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerabEPSS 1.2%CVE-2018-10627CRITICALEchelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versionsEPSS 1.2%CVE-2018-7496—An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header and referrer-policy reEPSS 1.2%CVE-2018-5477—An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 aEPSS 1.2%CVE-2017-9628—An Information Exposure issue was discovered in Saia Burgess Controls PCD Controllers with PCD firmware versions prior to 1.28.16 or 1.24.69EPSS 1.2%CVE-2023-45725—Apache CouchDB, IBM Cloudant: Privilege Escalation Using _design DocumentsEPSS 1.2%CVE-2024-51739HIGHUsers enumeration allowed through Rest API in Combodo iTopEPSS 1.2%CVE-2023-45348—Apache Airflow: Configuration information leakage vulnerabilityEPSS 1.2%CVE-2023-41752HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.2%CVE-2021-22917—Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowiEPSS 1.2%CVE-2020-2022HIGHPAN-OS: Panorama session disclosure during context switch into managed deviceEPSS 1.2%CVE-2022-32742MEDIUMA flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill thEPSS 1.2%CVE-2025-53728MEDIUMMicrosoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityEPSS 1.2%CVE-2024-30570MEDIUMAn information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication EPSS 1.2%CVE-2024-43416HIGHGLPI vulnerable to enumeration of users' email addresses by unauthenticated userEPSS 1.2%