Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-6248CRITICALData leakage and arbitrary remote code execution in Syrus cloud devicesEPSS 1.2%CVE-2018-0109—A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access sensitive data about the application.EPSS 1.2%CVE-2017-16741—An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0EPSS 1.2%CVE-2025-58751LOWVite middleware may serve files starting with the same name with the public directoryEPSS 1.2%CVE-2021-29483CRITICALwikiconfig API leaked private config variables set through ManageWikiEPSS 1.2%CVE-2020-25192MEDIUMMOXA NPort IAW5000A-I/O SeriesEPSS 1.2%CVE-2022-23982MEDIUMWordPress Perfect Brands for WooCommerce plugin <= 2.0.4 - Server Information Exposure vulnerabilityEPSS 1.2%CVE-2024-0716LOWByzoro Smart S150 Management Platform Backup File download.php information disclosureEPSS 1.2%CVE-2023-43804MEDIUM`Cookie` HTTP header isn't stripped on cross-origin redirectsEPSS 1.2%CVE-2024-29987MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.2%CVE-2017-6793—A vulnerability in the Inventory Management feature of Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attaEPSS 1.2%CVE-2022-46651—Apache Airflow: Security vulnerability on AirFlow ConnectionsEPSS 1.2%CVE-2023-5070MEDIUMSocial Media Share Buttons & Social Sharing Icons <= 2.8.5 - Information ExposureEPSS 1.2%CVE-2023-0836HIGHAn information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.EPSS 1.2%CVE-2021-25375MEDIUMUsing predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emaEPSS 1.2%CVE-2021-32731MEDIUMThe reset password form reveal users email addressEPSS 1.2%CVE-2024-8852MEDIUMAll-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error LogsEPSS 1.2%CVE-2019-1692MEDIUMCisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure VulnerabilityEPSS 1.2%CVE-2023-40029CRITICALCluster secret might leak in cluster details page in Argo CDEPSS 1.2%CVE-2019-7005MEDIUMUnauthenticated Information Disclosure Vulnerability in IP OfficeEPSS 1.2%