Fallos del tipo CWE-200

4917 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-48671HIGH Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A remote attacker could potentially exploit tEPSS 0.8%CVE-2026-44486HIGHAxios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionEPSS 0.8%CVE-2023-28444CRITICALangular-server-side-configuration information disclosure vulnerability in monorepo with node.js backendEPSS 0.8%CVE-2024-33437HIGHAn issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS Style RulesEPSS 0.8%CVE-2024-34708MEDIUMDirectus allows redacted data extraction on the API through "alias"EPSS 0.8%CVE-2024-29384HIGHAn issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functEPSS 0.8%CVE-2024-29961HIGHsupply-chain attack riskEPSS 0.8%CVE-2018-19947MEDIUMThe vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disEPSS 0.8%CVE-2023-27591HIGHUnauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metricsEPSS 0.8%CVE-2022-35249MEDIUMA information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages EPSS 0.8%CVE-2023-39519HIGHCloudExplorer Lite sensitive information leakage vulnerabilityEPSS 0.8%CVE-2023-50263LOWNautobot allows unauthenticated db-file-storage viewsEPSS 0.8%CVE-2020-26220LOWInformation exposure in touchbase.aiEPSS 0.8%CVE-2026-24098MEDIUMApache Airflow: Assigning single DAG permission leaked all DAGs Import ErrorsEPSS 0.8%CVE-2022-32740LOWInformation disclosure in the External InterfaceEPSS 0.8%CVE-2023-4917MEDIUMLeyka <= 3.30.7 - Authenticated (Subscriber+) Sensitive Information ExposureEPSS 0.8%CVE-2022-36074MEDIUMAuthentication headers exposed on by Nextcloud ServerEPSS 0.8%CVE-2024-32870MEDIUMiTop hub connector Information disclosureEPSS 0.8%CVE-2024-33309HIGHAn issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information viEPSS 0.8%CVE-2023-22577CRITICALWhite Rabbit Switch - Password Disclosure VulnerabilityEPSS 0.8%