Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-42878MEDIUMFacturaScripts: Unauthenticated phpinfo() Disclosure via Installer Endpoint in FacturaScriptsEPSS 0.9%CVE-2021-25110—Futurio Extra < 1.6.3 - Subscriber+ User Email Address DisclosureEPSS 0.9%CVE-2021-33709—A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versionEPSS 0.9%CVE-2023-43796MEDIUMSynapse vulnerable to leak of remote user device informationEPSS 0.9%CVE-2021-39163LOWAdding a private/unlisted room to a community exposes room metadata in an unauthorised manner.EPSS 0.9%CVE-2017-15138MEDIUMThe OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidentiaEPSS 0.9%CVE-2022-31190MEDIUMMetadata of withdrawn Items is exposed to anonymous users in DSpace XMLUIEPSS 0.9%CVE-2026-21532HIGHAzure Function Information Disclosure VulnerabilityEPSS 0.9%CVE-2023-26476HIGHTwo XWiki Platform UIs Expose Sensitive Information to an Unauthorized ActorEPSS 0.9%CVE-2017-12310—A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sEPSS 0.9%CVE-2023-6101MEDIUMMaiwei Safety Production Control Platform Intelligent Monitoring ha.html information disclosureEPSS 0.9%CVE-2022-27633MEDIUMAn information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specEPSS 0.9%CVE-2022-31134MEDIUMZulip Server public data export contains attachments that are non-publicEPSS 0.9%CVE-2022-27630MEDIUMAn information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A spEPSS 0.9%CVE-2022-31162HIGHSlack Morphism for Rust before 0.41.0 can accidentally leak Slack OAuth client information in application debug logsEPSS 0.9%CVE-2024-23321HIGHApache RocketMQ: Unauthorized Exposure of Sensitive DataEPSS 0.9%CVE-2021-24164—Ninja Forms < 3.4.34.1 - Authenticated OAuth Connection Key DisclosureEPSS 0.9%CVE-2023-7094MEDIUMNetentsec NS-ASG Application Security Gateway nsasg6.0.tgz information disclosureEPSS 0.9%CVE-2025-59716MEDIUMownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insEPSS 0.9%CVE-2013-10007MEDIUMethitter WP-Print-Friendly wp-print-friendly.php information disclosureEPSS 0.9%