Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2017-20019MEDIUMSolare Solar-Log Config information disclosureEPSS 1.0%CVE-2017-20110MEDIUMTeleopti WFM Administration Credentials information disclosureEPSS 1.0%CVE-2023-35934MEDIUMyt-dlp File Downloader cookie leakEPSS 1.0%CVE-2023-40023MEDIUMYaklang Plugin's Fuzztag Component Allows Unauthorized Local File ReadingEPSS 1.0%CVE-2023-39999MEDIUMWordPress < 6.3.2 is vulnerable to Broken Access ControlEPSS 1.0%CVE-2022-3348MEDIUMExposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljetEPSS 1.0%CVE-2024-28849MEDIUMProxy-Authorization header kept across hosts in follow-redirectsEPSS 1.0%CVE-2024-26470HIGHA host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackeEPSS 1.0%CVE-2022-29232MEDIUMExposure of messages in BigBlueButton public chatsEPSS 1.0%CVE-2020-11033MEDIUMAble to read any token through API user endpoint in GLPIEPSS 1.0%CVE-2022-25594MEDIUMMicroprogram parking lot management system - Exposure of Sensitive Information to an Unauthorized ActorEPSS 1.0%CVE-2023-0994HIGHExposure of Sensitive Information to an Unauthorized Actor in francoisjacquet/rosariosisEPSS 1.0%CVE-2025-59284LOWWindows NTLM Spoofing VulnerabilityEPSS 1.0%CVE-2019-15592—GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associatEPSS 1.0%CVE-2022-24784LOWDiscoverability of user password hash in Statamic CMSEPSS 1.0%CVE-2022-22183HIGHJunos OS Evolved: A remote attacker may cause a CPU Denial of Service by sending genuine traffic to a device on a specific IPv4 port.EPSS 1.0%CVE-2021-32473—It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to EPSS 1.0%CVE-2021-4377MEDIUMDoneren met Mollie <= 2.8.4 - Information DisclosureEPSS 1.0%CVE-2019-15579—An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where thEPSS 1.0%CVE-2018-25081HIGHBitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have beEPSS 1.0%