Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-24782MEDIUMSecure category names leaked via user activity export in DiscourseEPSS 1.0%CVE-2023-42387—An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via get_db_info function EPSS 1.0%CVE-2026-2055MEDIUMD-Link DIR-605L/DIR-619L DHCP Client Information information disclosureEPSS 1.0%CVE-2026-2056MEDIUMD-Link DIR-605L/DIR-619L DHCP Connection Status wan_connection_status.asp information disclosureEPSS 1.0%CVE-2026-2054MEDIUMD-Link DIR-605L/DIR-619L Wifi Setting information disclosureEPSS 1.0%CVE-2023-1584HIGHQuarkus-oidc: id and access tokens leak via the authorization code flowEPSS 1.0%CVE-2022-32818MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5. An app may be able to leak sensitive kernEPSS 1.0%CVE-2021-22785HIGHA CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leEPSS 1.0%CVE-2021-3644—A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressiEPSS 1.0%CVE-2023-34236HIGHInformation Disclosure Vulnerability in Weave GitOps Terraform ControllerEPSS 1.0%CVE-2021-22793—A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7)EPSS 1.0%CVE-2021-34125—An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via varioEPSS 1.0%CVE-2023-6076MEDIUMPHPGurukul Restaurant Table Booking System Reservation Status booking-details.php information disclosureEPSS 1.0%CVE-2022-31032MEDIUMResources of private projects can be exposed in TuleapEPSS 1.0%CVE-2025-6239MEDIUMInformation disclosureEPSS 1.0%CVE-2025-24102CRITICALThe issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 1EPSS 1.0%CVE-2024-30096MEDIUMWindows Cryptographic Services Information Disclosure VulnerabilityEPSS 1.0%CVE-2022-2558—Simple Job Board < 2.10.0 - Resume Disclosure via Directory ListingEPSS 1.0%CVE-2022-4543MEDIUMA flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR bEPSS 1.0%CVE-2024-0569MEDIUMTotolink T8 Setting cstecgi.cgi getSysStatusCfg information disclosureEPSS 1.0%