Fallos del tipo CWE-200

4926 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2019-3016MEDIUMIn a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in theEPSS 0.6%CVE-2023-22847MEDIUMInformation disclosure vulnerability exists in pg_ivm versions prior to 1.5.1. An Incrementally Maintainable Materialized View (IMMV) createEPSS 0.6%CVE-2026-9289MEDIUMWordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API EndpointsEPSS 0.6%CVE-2023-27894MEDIUMSensitive Information Disclosure in the SAP BusinessObjects Business Intelligence platformEPSS 0.6%CVE-2025-23173HIGHThe Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By defaEPSS 0.6%CVE-2024-10285CRITICALCE21 Suite <= 2.2.0 - JWT Token DisclosureEPSS 0.6%CVE-2024-13110MEDIUMBeijing Yunfan Internet Technology Yunfan Learning Examination System Exam Answer PaperController.java, information disclosureEPSS 0.6%CVE-2014-125102MEDIUMBestwebsoft Relevant Plugin Thumbnail information disclosureEPSS 0.6%CVE-2021-25649MEDIUMAvaya Utility Services Sensitive Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-2792MEDIUMEphemeral messages return private channel contents in permalink previewsEPSS 0.6%CVE-2023-36507MEDIUMWordPress BookingPress Plugin <= 1.0.64 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2026-51027CRITICALAn issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.EPSS 0.6%CVE-2023-30993MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2022-31046MEDIUMInformation Disclosure via Export Module in TYPO3 CMSEPSS 0.6%CVE-2026-31909HIGHApache OFBiz: Unauthenticated Shipment Label Image DisclosureEPSS 0.6%CVE-2023-40002MEDIUMWordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2026-70478CRITICALFlowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected serviceEPSS 0.6%CVE-2026-72548HIGHOpenSignLabs OpenSign - Information DisclosureEPSS 0.6%CVE-2024-11265MEDIUMWp Maximum Upload File Size <= 1.1.3 - Authenticated (Author+) Full Path DisclosureEPSS 0.6%CVE-2023-6214HIGHHT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_productsEPSS 0.6%