Fallos del tipo CWE-200

4898 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-31133HIGHGhost vulnerable to disclosure of private API fieldsEPSS 45.7%CVE-2019-3993—ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's EPSS 45.7%CVE-2024-6646MEDIUMNetgear WN604 Web Interface downloadFile.php information disclosureEPSS 45.7%CVE-2025-31486MEDIUMVite allows server.fs.deny to be bypassed with .svg or relative pathsEPSS 40.5%CVE-2022-45354MEDIUMWordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data ExposureEPSS 38.1%CVE-2008-0655HIGHMultiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.EPSS 37.9%KEVCVE-2022-22733—Access-Token in ElasticJob UI causes password disclosureEPSS 37.6%CVE-2020-7387MEDIUMSage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized ActorEPSS 36.4%CVE-2025-52488HIGHDNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputEPSS 35.8%CVE-2023-41323MEDIUMUsers login enumeration by unauthenticated user in GLPIEPSS 33.9%CVE-2024-3274MEDIUMD-Link DNS-320L/DNS-320LW/DNS-327L HTTP GET Request info.cgi information disclosureEPSS 33.5%CVE-2021-21816MEDIUMAn information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request cEPSS 32.4%CVE-2023-39677—MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information discloEPSS 32.3%CVE-1999-0524MEDIUMICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.EPSS 32.2%CVE-2024-7339MEDIUMTVT DVR TD-2104TS-CL queryDevInfo information disclosureEPSS 32.0%CVE-2026-20133MEDIUMA vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affectEPSS 31.8%KEVCVE-2025-50154MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 30.2%CVE-2024-53991HIGHPotential Backup file leaked via Nginx in DiscourseEPSS 29.9%CVE-2025-68686MEDIUMAn Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,EPSS 29.6%KEVCVE-2021-38314MEDIUMGutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information DisclosureEPSS 29.0%