Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-24408MEDIUMAdobe Commerce | Information Exposure (CWE-200)EPSS 1.0%CVE-2021-22721—A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink ParkingEPSS 1.0%CVE-2022-32220MEDIUMAn information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messageEPSS 1.0%CVE-2022-41939MEDIUMCredential exposure when running third-party builders in knative/funcEPSS 1.0%CVE-2022-29241HIGHKnown or guessable hidden files may be accessed in Jupyter ServerEPSS 0.9%CVE-2026-40379CRITICALAzure Entra ID Spoofing VulnerabilityEPSS 0.9%CVE-2017-6040—An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitivEPSS 0.9%CVE-2026-0717MEDIUMLottieFiles – Lottie block for Gutenberg <= 3.0.0 - Unauthenticated Sensitive Information ExposureEPSS 0.9%CVE-2021-36095MEDIUMUser enumeration issue using "lost password" featureEPSS 0.9%CVE-2022-31068MEDIUMSensitive Data Exposure on Refused Inventory Files in GLPIEPSS 0.9%CVE-2021-39203MEDIUMPrivate data disclosure/privilege escalation through the block editor in WordpressEPSS 0.9%CVE-2020-15080MEDIUMInformation disclosure in release archive in PrestaShopEPSS 0.9%CVE-2022-2907MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 beforeEPSS 0.9%CVE-2025-24253CRITICALThis issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 1EPSS 0.9%CVE-2021-42536HIGHEmerson WirelessHART GatewayEPSS 0.9%CVE-2024-21140MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: HotspotEPSS 0.9%CVE-2023-39620—An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via thEPSS 0.9%CVE-2024-34788MEDIUMAn improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially senEPSS 0.9%CVE-2019-15963MEDIUMCisco Unified Communications Manager Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-47855CRITICALAn exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3EPSS 0.9%