Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2020-14371—A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are runEPSS 0.9%CVE-2022-41859HIGHIn freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantiallEPSS 0.9%CVE-2022-24804MEDIUMPrivate group name exposure in discourseEPSS 0.9%CVE-2022-39309MEDIUMGoCD server secret encryption/decryption key leaked to agents during material serializationEPSS 0.9%CVE-2022-2939MEDIUMWP Cerber Security <= 9.0 - User Enumeration BypassEPSS 0.9%CVE-2014-125093MEDIUMAd Blocking Detector Plugin ad-blocking-detector.php information disclosureEPSS 0.9%CVE-2018-1059—The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing EPSS 0.9%CVE-2021-32624HIGHPrivate Field data leakEPSS 0.9%CVE-2023-0321CRITICALDisclosure of Sensitive Information on Campbell Scientific ProductsEPSS 0.9%CVE-2019-19283—A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive information about tEPSS 0.9%CVE-2022-32219MEDIUMAn information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter frEPSS 0.9%CVE-2020-4079HIGHInformation disclosure vulnerability in iTopEPSS 0.9%CVE-2026-50415MEDIUMWindows Media Information Disclosure VulnerabilityEPSS 0.9%CVE-2023-24069—Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages froEPSS 0.9%CVE-2025-43542HIGHThis issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOEPSS 0.9%CVE-2026-55993HIGHApache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviourEPSS 0.9%CVE-2026-46726HIGHApache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headersEPSS 0.9%CVE-2021-43792MEDIUMNotifications leak in DiscourseEPSS 0.9%CVE-2024-6569MEDIUMCampaign Monitor for WordPress <= 2.8.15 - Unauthenticated Full Path DisclosureEPSS 0.9%CVE-2022-47070HIGHNVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the secoEPSS 0.9%