Fallos del tipo CWE-200

4925 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-25057MEDIUMWordPress Libsyn Publisher Hub Plugin <= 1.3.2 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2026-43646HIGHApache Wicket: crafted URLs can bypass PackageResourceGuardEPSS 0.6%CVE-2022-41862LOWIn PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption.EPSS 0.6%CVE-2026-60023HIGHApache Answer: Unauthorized disclosure of deleted or pending answer contentEPSS 0.6%CVE-2025-7654HIGHMultiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel LibraryEPSS 0.6%CVE-2023-42490HIGH EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.6%CVE-2022-46355HIGHA vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALAEPSS 0.6%CVE-2025-47969MEDIUMWindows Virtualization-Based Security (VBS) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-39053—An information leak in Hattoriya v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-39051—An information leak in VISION MEAT WORKS Track Diner 10/10mbl v13.6.1 allows attackers to obtain the channel access token and send crafted mEPSS 0.6%CVE-2025-22612CRITICALCoolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE)EPSS 0.6%CVE-2023-39050—An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-39048—An information leak in Tokudaya.honten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-39042—An information leak in Gyouza-newhushimi v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-39057—An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2024-54467MEDIUMA cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS SequoiEPSS 0.6%CVE-2023-39054—An information leak in Tokudaya.ekimae_mc v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-25913HIGHAuthentication Bypass in Danfoss AK-SM800AEPSS 0.6%CVE-2026-54489CRITICALDell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerEPSS 0.6%CVE-2024-7697HIGHLogical vulnerability in com.transsion.carlcareEPSS 0.6%