Fallos del tipo CWE-200

4919 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-7328MEDIUMYouDianCMS information disclosureEPSS 0.7%CVE-2021-23193HIGHImproper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators EPSS 0.7%CVE-2021-36091LOWUnautorized access to the calendar appointmentsEPSS 0.7%CVE-2021-23204HIGHExposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be eEPSS 0.7%CVE-2024-35230MEDIUMWelcome and About GeoServer pages communicate version and revision informationEPSS 0.7%CVE-2019-3811MEDIUMA vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead oEPSS 0.7%CVE-2026-65017MEDIUMApache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)EPSS 0.7%CVE-2025-15082MEDIUMTOZED ZLT M30s Web Management proc_post information disclosureEPSS 0.7%CVE-2024-23662MEDIUMAn exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 thEPSS 0.7%CVE-2023-48294MEDIUMBroken Access control on Graphs Feature in LibreNMSEPSS 0.7%CVE-2023-6105MEDIUMManageEngine Information Disclosure in Multiple ProductsEPSS 0.7%CVE-2025-53066HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). EPSS 0.7%CVE-2022-47410CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2022-47411CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2021-39089MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.7%CVE-2018-3826—In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameEPSS 0.7%CVE-2024-29898MEDIUMOversight in fix for GHSA-4rcf-3cj2-46mq may have exposed suppressed wiki requests on private wikisEPSS 0.7%CVE-2026-26014MEDIUMPion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authentication keyEPSS 0.7%CVE-2025-34220MEDIUMVasion Print (formerly PrinterLogic) Unauthenticated API Leaks Group InformationEPSS 0.7%CVE-2026-20932MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 0.7%