Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-48258MEDIUMIn Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.EPSS 1.1%CVE-2026-26897CRITICALAn issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive informatioEPSS 1.1%CVE-2026-50429HIGHWindows Kernel Information Disclosure VulnerabilityEPSS 1.1%CVE-2023-38499LOWtypo3/cms-core Information Disclosure due to Out-of-scope Site ResolutionEPSS 1.1%CVE-2018-16467—A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.EPSS 1.1%CVE-2022-31130MEDIUMGrafana data source and plugin proxy endpoints leaking authentication tokens to some destination pluginsEPSS 1.1%CVE-2026-41615CRITICALMicrosoft Authenticator Information Disclosure VulnerabilityEPSS 1.1%CVE-2021-21421HIGHApiKey secret could be revelated on network issueEPSS 1.1%CVE-2022-24906LOWError in deleting deck cards attachment reveals the full application path in Nextcloud DeckEPSS 1.1%CVE-2022-31060MEDIUMBanner topic data is exposed on login-required Discourse sitesEPSS 1.1%CVE-2026-45539HIGHMicrosoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project treeEPSS 1.1%CVE-2024-43610HIGHCopilot Studio Information Disclosure VulnerabilityEPSS 1.1%CVE-2024-31869MEDIUMApache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config usedEPSS 1.1%CVE-2021-4024—A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spaEPSS 1.1%CVE-2023-1203—Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Manager PowerShell ModuEPSS 1.1%CVE-2021-39223MEDIUMFile path disclosure of shared files in Richdocuments applicationEPSS 1.1%CVE-2022-20680MEDIUMCisco Prime Service Catalog Information Disclosure VulnerabilityEPSS 1.1%CVE-2021-22770—A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensitive information to anEPSS 1.1%CVE-2023-49068—Apache DolphinScheduler: Information Leakage VulnerabilityEPSS 1.1%CVE-2018-16866MEDIUMAn out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attackerEPSS 1.1%