Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-47633HIGHMicrosoft Cost Management Information Disclosure VulnerabilityEPSS 1.0%CVE-2024-21501MEDIUMVersions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attriEPSS 1.0%CVE-2023-26054MEDIUMCredentials inlined to Git URLs could end up in provenance attestation in BuildKitEPSS 1.0%CVE-2019-18334—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.0%CVE-2019-18333—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.0%CVE-2019-18335—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.0%CVE-2019-18331—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.0%CVE-2022-29235MEDIUMLimited data exposure for shared external videos in BigBlueButtonEPSS 1.0%CVE-2026-45793HIGHComposer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logsEPSS 1.0%CVE-2021-21301LOWVideo feed was captured while user has disabled videoEPSS 1.0%CVE-2022-46163HIGHtravel-support-program vulnerable to data exfiltration via Ransack query injectionEPSS 1.0%CVE-2021-39192MEDIUMPrivilege escalation: all users can access Admin-level API keysEPSS 1.0%CVE-2019-14839—It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password whenEPSS 1.0%CVE-2020-15235MEDIUMSensitive data exposure in RACTFEPSS 1.0%CVE-2019-15578—An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The patEPSS 1.0%CVE-2023-42505MEDIUMApache Superset: Sensitive information disclosure on db connection detailsEPSS 1.0%CVE-2022-32984HIGHBTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sEPSS 1.0%CVE-2017-7510—In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.EPSS 1.0%CVE-2023-32271MEDIUMAn information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS PlatEPSS 1.0%CVE-2021-35527HIGHPassword Autocomplete Vulnerability in Hitachi ABB Power Grids eSOMS ApplicationEPSS 1.0%