Fallos del tipo CWE-200

4927 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-48333MEDIUMWordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2025-9005MEDIUMmtons mblog register information exposureEPSS 0.6%CVE-2022-43951MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 anEPSS 0.6%CVE-2024-21209LOWVulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.4.2 anEPSS 0.6%CVE-2024-4022MEDIUMKeenetic KN-1010/KN-1410/KN-1711/KN-1810/KN-1910 Version Data version.js information disclosureEPSS 0.6%CVE-2025-59240MEDIUMMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.6%CVE-2022-28224MEDIUMCalico and Calico Enterprise may be vulnerable to route hijacking with the floating IP featureEPSS 0.6%CVE-2024-47771HIGHElement Desktop vulnerable to potential exposure of access token via authenticated mediaEPSS 0.6%CVE-2024-4583MEDIUMFaraday GM8181/GM828x Request information disclosureEPSS 0.6%CVE-2026-73411MEDIUMShescape: Home-directory disclosure in assignment context on Unix with DashEPSS 0.6%CVE-2023-39289—A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attackEPSS 0.6%CVE-2023-23624MEDIUMDiscourse's exclude_tags param could leak which topics had a specific hidden tagEPSS 0.6%CVE-2023-6136MEDIUMWordPress Debug Log Manager Plugin <= 2.3.0 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2019-14802MEDIUMHashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template renderinEPSS 0.6%CVE-2024-13911HIGHDatabase Backup and check Tables Automated With Scheduler 2024 <= 2.35 - Authenticated (Administrator+) Sensitive Information ExposureEPSS 0.6%CVE-2020-10264HIGHRTDE Interface allows unauthenticated reading of robot data and unauthenticated writing of registers and outputsEPSS 0.6%CVE-2023-3779MEDIUMEssential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key DisclosureEPSS 0.6%CVE-2024-4173HIGHSANnav versions exposes Kafka in the wan interface.EPSS 0.6%CVE-2024-10290MEDIUMZZCMS inc.php information disclosureEPSS 0.6%CVE-2026-32609HIGHGlances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP CredentialsEPSS 0.6%