Fallos del tipo CWE-200

4917 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-22577CRITICALWhite Rabbit Switch - Password Disclosure VulnerabilityEPSS 0.8%CVE-2021-21596CRITICALDell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2024-33309HIGHAn issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information viEPSS 0.8%CVE-2023-5576HIGHMigration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret ExposureEPSS 0.7%CVE-2025-27675CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Vulnerable OpenID Implementation V-EPSS 0.7%CVE-2013-10030MEDIUMExit Box Lite Plugin wordpress-exit-box-lite.php information disclosureEPSS 0.7%CVE-2023-27478MEDIUMDisclosure of unrelated data in libmemcached-awesome EPSS 0.7%CVE-2022-39307MEDIUMGrafana subject to Exposure of Sensitive Information resulting in User enumeration via forget passwordEPSS 0.7%CVE-2024-23302HIGHCouchbase Server before 7.2.4 has a private key leak in goxdcr.log.EPSS 0.7%CVE-2023-40049MEDIUMWS_FTP Server Information Disclosure via Directory ListingEPSS 0.7%CVE-2020-12518MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.EPSS 0.7%CVE-2023-49981HIGHA directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the EPSS 0.7%CVE-2023-20055HIGHCisco DNA Center Privilege Escalation VulnerabilityEPSS 0.7%CVE-2023-32082LOWetcd key name can be accessed via LeaseTimeToLive APIEPSS 0.7%CVE-2026-2861MEDIUMFoswiki Changes/Viewfile/Oops information disclosureEPSS 0.7%CVE-2025-45620HIGHAn issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted requestEPSS 0.7%CVE-2022-31177LOWPossible to infer sensitive information through query strings in Flask-AppBuilderEPSS 0.7%CVE-2021-20250—A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on theEPSS 0.7%CVE-2022-45103MEDIUM Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerabiEPSS 0.7%