Fallos del tipo CWE-200

4920 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-1968HIGHAuthorization Header Leakage in scrapy/scrapy on Scheme Change RedirectsEPSS 0.7%CVE-2022-23726MEDIUMPingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amoEPSS 0.7%CVE-2026-55500CRITICAL9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database TakeoverEPSS 0.7%CVE-2023-23978MEDIUMWordPress WP Client Reports Plugin <= 1.0.16 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2022-24762MEDIUMExposure of Sensitive Information to an Unauthorized Actor in sysend.jsEPSS 0.7%CVE-2023-33174MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.7%CVE-2017-20178LOWCodiad process.php saveJSON information disclosureEPSS 0.7%CVE-2021-40360—A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versionEPSS 0.7%CVE-2023-44253MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 aEPSS 0.7%CVE-2023-4139HIGHWP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory ListingEPSS 0.7%CVE-2022-36101MEDIUMSensitive data in backend customer moduleEPSS 0.7%CVE-2024-23962MEDIUMAlpine Halo9 Missing AuthenticationEPSS 0.7%CVE-2024-32816HIGHWordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerabilityEPSS 0.7%CVE-2024-32781HIGHWordPress Email Customizer for WooCommerce plugin <= 2.6.0 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2024-1643CRITICALUnauthorized Organization Access in lunary-ai/lunaryEPSS 0.7%CVE-2019-25210CRITICALAn issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flEPSS 0.7%CVE-2024-32726HIGHWordPress Frontend Dashboard plugin <= 2.2.2 - Sensitive Data Exposure on PII vulnerabilityEPSS 0.7%CVE-2022-39212MEDIUMLast video frame is still sent after video is disabled in a call in Nextcloud TalkEPSS 0.7%CVE-2026-75915HIGHCodeWhale before 0.8.64 Environment Variable Leak via js_executionEPSS 0.7%CVE-2023-6615LOWTypecho manage-users.php information disclosureEPSS 0.7%