Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2018-11728MEDIUMThe libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attaEPSS 1.2%CVE-2023-28271MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 1.2%CVE-2021-22135—Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API EPSS 1.2%CVE-2026-26273CRITICALKnown affected by Account Takeover via Password Reset Token LeakageEPSS 1.2%CVE-2025-47966CRITICALPower Automate Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2021-31381MEDIUMSRC Series: A remote attacker sending a specially crafted query may cause the web server to delete filesEPSS 1.2%CVE-2024-30472HIGHTelemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with loEPSS 1.2%CVE-2019-13557—In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker tEPSS 1.2%CVE-2024-9821HIGHBot for Telegram on WooCommerce <= 1.2.7 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication BypassEPSS 1.2%CVE-2007-3650MEDIUMmyWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached EPSS 1.2%CVE-2025-34130HIGHLILIN DVR Arbitrary File Read via net_html.cgiEPSS 1.1%CVE-2024-1098MEDIUMRebuild proxy-download QiniuCloud.getStorageFile information disclosureEPSS 1.1%CVE-2021-32707MEDIUMBypass of image blocking in Nextcloud MailEPSS 1.1%CVE-2022-22680MEDIUMExposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42EPSS 1.1%CVE-2022-31139MEDIUMNo security checking for UnsafeAccess.getInstance() in UnsafeAccessorEPSS 1.1%CVE-2017-20101LOWProjectSend information disclosureEPSS 1.1%CVE-2019-11282MEDIUMUAA is vulnerable to a Blind SCIM injection leading to information disclosureEPSS 1.1%CVE-2017-2654LOWjenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dyEPSS 1.1%CVE-2021-31380MEDIUMSRC Series: A remote attacker sending a specially crafted query may cause the web server to disclose sensitive informationEPSS 1.1%CVE-2024-21147HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: HotspotEPSS 1.1%