Fallos del tipo CWE-200

4915 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2021-44172LOWAn exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 EPSS 0.9%CVE-2021-33727—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profiEPSS 0.9%CVE-2024-38650CRITICALAn authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.EPSS 0.9%CVE-2026-25475MEDIUMOpenClaw Vulnerable to Local File Inclusion via MEDIA: Path ExtractionEPSS 0.9%CVE-2023-0027MEDIUMRockwell Automation Modbus TCP AOI Server Could Leak Sensitive InformationEPSS 0.8%CVE-2022-31143MEDIUMLeak of sensitive information through login page error in GLPIEPSS 0.8%CVE-2023-24923MEDIUMMicrosoft OneDrive for Android Information Disclosure VulnerabilityEPSS 0.8%CVE-2024-45791HIGHApache HertzBeat: Exposure sensitive token via http GET method with query stringEPSS 0.8%CVE-2022-4415MEDIUMA vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suEPSS 0.8%CVE-2024-39676HIGHApache Pinot: Unauthorized endpoint exposed sensitive informationEPSS 0.8%CVE-2021-37703MEDIUMInformation exposure in DiscourseEPSS 0.8%CVE-2024-28442HIGHDirectory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via tEPSS 0.8%CVE-2023-5256HIGHDrupal core - Critical - Cache poisoning - SA-CORE-2023-006EPSS 0.8%CVE-2025-34185HIGHIlevia EVE X1 Server 4.7.18.0.eden Unauthenticated File DisclosureEPSS 0.8%CVE-2023-2446MEDIUMUserPro <= 5.1.1 - Sensitive Information Disclosure via ShortcodeEPSS 0.8%CVE-2021-32750MEDIUMDe-anonymization via messageEPSS 0.8%CVE-2023-5692MEDIUMWordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalinkEPSS 0.8%CVE-2020-1777MEDIUMAgent names disclosed in chat featureEPSS 0.8%CVE-2021-31371MEDIUMJunos OS: QFX5000 Series: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces.EPSS 0.8%CVE-2024-39210HIGHBest House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php.EPSS 0.8%