Fallos del tipo CWE-200

4919 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-29197MEDIUMPimcore Preview Documents are not restricted to logged in users anymoreEPSS 0.7%CVE-2022-32805MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, maEPSS 0.7%CVE-2026-61899HIGHApache Tapestry: Possible classpath file download through URL manipulationEPSS 0.7%CVE-2025-21214MEDIUMWindows BitLocker Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-43410MEDIUMJenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling throEPSS 0.7%CVE-2023-33857MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.7%CVE-2025-1606MEDIUMSourceCodester Best Employee Management System backups.php information disclosureEPSS 0.7%CVE-2025-54376HIGHHoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.EPSS 0.7%CVE-2024-27769HIGHUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.7%CVE-2026-23486MEDIUMBlinko: Unauthorized User Information LeakEPSS 0.7%CVE-2024-31207MEDIUMVite's `server.fs.deny` did not deny requests for patterns with directoriesEPSS 0.7%CVE-2022-42883MEDIUMWordPress Quiz And Survey Master plugin <= 7.3.10 - Sensitive Information Disclosure vulnerabilityEPSS 0.7%CVE-2023-29287MEDIUMAdobe Commerce Information Exposure Security feature bypassEPSS 0.7%CVE-2023-28762CRITICALInformation Disclosure in SAP BusinessObjects Intelligence PlatformEPSS 0.7%CVE-2024-29897MEDIUMCreateWiki Leak of suppressed wiki requests outside of `CreateWikiGlobalWiki`EPSS 0.7%CVE-2024-28235HIGHContao possible cookie sharing with external domains while checking protected pages for broken linksEPSS 0.7%CVE-2024-52508HIGHNextcloud Mail auto configurator can be tricked into sending account information to wrong serversEPSS 0.7%CVE-2022-4054MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5EPSS 0.7%CVE-2022-39031MEDIUMSmart eVision - Exposure of Sensitive Information to an Unauthorized Actor -3EPSS 0.7%CVE-2020-5414MEDIUMApp Autoscaler logs credentialsEPSS 0.7%