Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-3689LOWZhejiang Land Zongheng Network Technology O2OA information disclosureEPSS 0.9%CVE-2025-56427HIGHDirectory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_EPSS 0.9%CVE-2024-1139HIGHCluster-monitoring-operator: credentials leakEPSS 0.9%CVE-2021-41123MEDIUMExposure of Sensitive Information to an Unauthorized Actor in WB.UI.Headquarters.dllEPSS 0.9%CVE-2021-32695LOWMalicious Android app could access Shared Preferences of the Nextcloud Android clientEPSS 0.9%CVE-2021-32720MEDIUMList of order ids, number, items total and token value exposed for unauthorized uses via new APIEPSS 0.9%CVE-2022-24849MEDIUMContact to DisCatSharp-owned server using authenticated clientEPSS 0.9%CVE-2021-3566—Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file tEPSS 0.9%CVE-2022-40177—A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 0.9%CVE-2021-27424MEDIUMGE UR family exposure of sensitive information to an unauthorized actorEPSS 0.9%CVE-2022-23497MEDIUMInsecure file access in FreshRSSEPSS 0.9%CVE-2021-39224LOWFile path disclosure of shared files in OfficeOnline applicationEPSS 0.9%CVE-2022-41707MEDIUMRelatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user of the application. TEPSS 0.9%CVE-2020-3547MEDIUMCisco Email Security Appliance, Cisco Content Security Management Appliance, and Cisco Web Security Appliance Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-87820MEDIUMCyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI ScannerEPSS 0.9%CVE-2026-47282MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.9%CVE-2021-1562MEDIUMCisco BroadWorks Application Server Information Disclosure VulnerabilityEPSS 0.9%CVE-2021-34702MEDIUMCisco Identity Services Engine Sensitive Information Disclosure VulnerabilityEPSS 0.9%CVE-2024-11961MEDIUMGuangzhou Huayi Intelligent Technology Jeewms WmOmNoticeHController.java preHandle information disclosureEPSS 0.9%CVE-2025-30474MEDIUMApache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error messageEPSS 0.9%