Fallos del tipo CWE-200

4920 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-48828MEDIUMApache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the keyEPSS 0.7%CVE-2026-48892MEDIUMApache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic optionsEPSS 0.7%CVE-2026-45192MEDIUMApache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API ResponseEPSS 0.7%CVE-2026-49487MEDIUMApache Airflow: Task-instance API exposes secrets in deferred trigger kwargsEPSS 0.7%CVE-2021-22143LOWElastic APM .NET Agent information disclosureEPSS 0.7%CVE-2026-55447CRITICALLangflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitEPSS 0.7%CVE-2026-69197HIGHUmbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansionEPSS 0.7%CVE-2022-1663—Stop Spam Comments <= 0.2.1.2 - Access Token BypassEPSS 0.7%CVE-2023-47126LOWInformation Disclosure in Install Tool in typo3/cms-installEPSS 0.7%CVE-2026-55553HIGHurllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakageEPSS 0.7%CVE-2023-20866MEDIUMIn Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive informatioEPSS 0.7%CVE-2022-45634MEDIUMAn issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain access to sensitive aEPSS 0.7%CVE-2019-15577—An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclEPSS 0.7%CVE-2024-33865HIGHAn issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GEPSS 0.7%CVE-2026-63646MEDIUMCordysCRM MCP Form Configuration Endpoint Exposed to Anonymous UsersEPSS 0.7%CVE-2023-44150HIGHWordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2026-42333MEDIUMquarkus-openapi-generator has overly broad path-parameter matching that sends authentication headers to unintended operationsEPSS 0.7%CVE-2021-22272MEDIUMControlTouch Cloud Service vulnerability: Serial Number can be misused during commissioning phase.EPSS 0.7%CVE-2023-3132MEDIUMMainWP Child <= 4.4.1.1 - Information Disclosure via Back-Up FilesEPSS 0.7%CVE-2023-30540LOWChat poll data can still be queried from API after purging history in Nextcloud talkEPSS 0.7%