Fallos del tipo CWE-200

4927 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-10290MEDIUMZZCMS inc.php information disclosureEPSS 0.6%CVE-2026-32609HIGHGlances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP CredentialsEPSS 0.6%CVE-2024-35171MEDIUMWordPress Academy LMS plugin <= 1.9.25 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-6562MEDIUMaffiliate-toolkit <= 3.5.5 - Unauthenticated Full Path DislcosureEPSS 0.6%CVE-2024-7414MEDIUMPDF Builder for WPForms <= 1.2.116 - Unauthenticated Full Path DisclosureEPSS 0.6%CVE-2024-34388HIGHWordPress GDPR Compliance plugin <= 1.2.5 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2023-39735HIGHThe leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadEPSS 0.6%CVE-2023-39737HIGHThe leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messaEPSS 0.6%CVE-2023-39739HIGHThe leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted brEPSS 0.6%CVE-2023-39736HIGHThe leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted brEPSS 0.6%CVE-2022-36777MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2024-0242HIGHUnauthorized access to settings in Qolsys IQ Panel 4 and IQ4 HubEPSS 0.6%CVE-2026-44881HIGHPortainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-UpdateEPSS 0.6%CVE-2024-44152HIGHA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be aEPSS 0.6%CVE-2023-1858MEDIUMSourceCodester Earnings and Expense Tracker App index.php information disclosureEPSS 0.6%CVE-2024-8884CRITICALCWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacEPSS 0.6%CVE-2025-63094HIGHXiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackersEPSS 0.6%CVE-2024-8326HIGHs2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.6%CVE-2026-55870LOWGoCD is vulnerable to credential exposure when admins insecurely configure material URLsEPSS 0.6%CVE-2022-2408MEDIUMGuest accounts can list all public channelsEPSS 0.6%