Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2017-20007MEDIUMInformation Exposure in INGEPAC DA AUEPSS 1.1%CVE-2025-55243HIGHMicrosoft OfficePlus Spoofing VulnerabilityEPSS 1.1%CVE-2021-21400HIGHEntering code in App Lock modal sends input to conversationEPSS 1.1%CVE-2025-1595MEDIUMAnhui Xufan Information Technology EasyCVR getbaseconfig information disclosureEPSS 1.1%CVE-2022-31176HIGHGrafana Image Renderer leaking filesEPSS 1.1%CVE-2021-32716MEDIUMInternal hidden fields are visible on to many associations in admin apiEPSS 1.1%CVE-2021-22134—A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. EPSS 1.1%CVE-2016-9590MEDIUMpuppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation oEPSS 1.1%CVE-2022-27863MEDIUMWordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 - Sensitive Data Exposure vulnerabilityEPSS 1.1%CVE-2021-22137—In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. SearcEPSS 1.1%CVE-2022-23984LOWWordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information DisclosureEPSS 1.1%CVE-2020-3193MEDIUMCisco Prime Collaboration Provisioning Information Disclosure VulnerabilityEPSS 1.1%CVE-2017-0881—An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server beforEPSS 1.1%CVE-2021-0210MEDIUMJunos OS: Privilege escalation in J-Web due to arbitrary command and code execution via information disclosure from another users active sessionEPSS 1.1%CVE-2021-43938HIGHElcomplus SmartPTT SCADA Server Information ExposureEPSS 1.1%CVE-2023-24838CRITICALHGiga PowerStation - Information LeakageEPSS 1.1%CVE-2021-22044—In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@ReEPSS 1.1%CVE-2025-24232CRITICALThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13EPSS 1.1%CVE-2025-43362CRITICALThe issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to mEPSS 1.1%CVE-2022-24747MEDIUMHTTP caching is marking private HTTP headers as publicEPSS 1.1%