Fallos del tipo CWE-200

4898 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-1999-0517MEDIUMAn SNMP community name is the default (e.g. public), null, or missing.EPSS 28.7%CVE-2022-23648HIGHInsecure handling of image volumes in containerd CRI pluginEPSS 27.4%CVE-2003-1567HIGHThe undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body oEPSS 25.2%CVE-2020-17527—Apache Tomcat: Request header mix-up between HTTP/2 streamsEPSS 24.6%CVE-2024-45309HIGHOneDev vulnerable to arbitrary file reading for unauthenticated userEPSS 24.5%CVE-2022-42979HIGHInformation disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ovEPSS 24.3%CVE-2025-8868CRITICALChef Automate compliance service SQL Injection VulnerabilityEPSS 24.3%CVE-2023-2916HIGHInfiniteWP Client <= 1.11.1 - Authenticated (Subscriber+) Sensitive Information ExposureEPSS 24.0%CVE-2024-27356HIGHAn issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical uEPSS 23.9%CVE-2024-30081HIGHWindows NTLM Spoofing VulnerabilityEPSS 23.8%CVE-2024-49357HIGHZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data LeakEPSS 23.7%CVE-2024-56902HIGHInformation disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account inEPSS 23.4%CVE-2015-5317HIGHThe Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name inEPSS 23.0%KEVCVE-2025-24071MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 22.9%CVE-2021-24122—Apache Tomcat information disclosureEPSS 22.9%CVE-2024-21320MEDIUMWindows Themes Spoofing VulnerabilityEPSS 22.8%CVE-2022-31711MEDIUMVMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and aEPSS 21.7%CVE-2024-38200MEDIUMMicrosoft Office Spoofing VulnerabilityEPSS 20.5%CVE-2023-38547CRITICALA vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access itsEPSS 18.9%CVE-2024-5230MEDIUMEnvaySoft FleetCart information disclosureEPSS 18.8%