Fallos del tipo CWE-200

4919 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-47029CRITICALAn issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted PEPSS 0.7%CVE-2023-26533MEDIUMWordPress Zippy Plugin <= 1.6.1 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2023-0659MEDIUMBDCOM 1704-WGL Backup File param.file.tgz information disclosureEPSS 0.7%CVE-2022-29916MEDIUMFirefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been usEPSS 0.7%CVE-2024-20019MEDIUMIn wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additionEPSS 0.7%CVE-2025-26795HIGHApache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driverEPSS 0.7%CVE-2025-26864HIGHApache IoTDB: Exposure of Sensitive Information in IoTDB OpenID AuthenticationEPSS 0.7%CVE-2022-35246MEDIUMA NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl MeteEPSS 0.7%CVE-2013-10024LOWExit Strategy Plugin exitpage.php information disclosureEPSS 0.7%CVE-2023-29106MEDIUMA vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versiEPSS 0.7%CVE-2022-34329MEDIUMIBM CICS TX information disclosureEPSS 0.7%CVE-2023-37868MEDIUMWordPress Premium Addons PRO Plugin <= 2.9.0 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2023-41259—Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in EPSS 0.7%CVE-2019-14820MEDIUMIt was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be EPSS 0.7%CVE-2024-28236HIGHInsecure Variable Substitution in VelaEPSS 0.7%CVE-2024-47532HIGHRestrictedPython information leakage via `AttributeError.obj` and the `string` moduleEPSS 0.7%CVE-2023-34093MEDIUMStrapi allows actors to make all attributes on a content-type public without noticing itEPSS 0.7%CVE-2026-41610MEDIUMVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2022-26423HIGHMISSING AUTHORIZATION CWE-862EPSS 0.7%CVE-2023-35625MEDIUMAzure Machine Learning Compute Instance for SDK Users Information Disclosure VulnerabilityEPSS 0.7%