Fallos del tipo CWE-200

4927 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-39925MEDIUMAn issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organizationEPSS 0.6%CVE-2023-27863MEDIUMIBM Spectrum Protect Plus Server information disclosureEPSS 0.6%CVE-2025-11647LOWTomofun Furbo 360/Furbo Mini GATT Service information disclosureEPSS 0.6%CVE-2023-46315—The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable DiEPSS 0.6%CVE-2024-4021MEDIUMKeenetic KN-1010/KN-1410/KN-1711/KN-1810/KN-1910 Configuration Setting ndmComponents.js information disclosureEPSS 0.6%CVE-2025-31492HIGHmod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected dataEPSS 0.6%CVE-2026-41323HIGHKyverno: ServiceAccount token leaked to external servers via apiCall service URLEPSS 0.6%CVE-2023-0614HIGHThe fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacEPSS 0.6%CVE-2024-27947MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwardEPSS 0.6%CVE-2024-24548HIGHPayment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise usEPSS 0.6%CVE-2024-56136MEDIUM/api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account in Zulip serverEPSS 0.6%CVE-2026-7167MEDIUMMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.6%CVE-2022-31095MEDIUMExposure of Sensitive Information in discourse-chatEPSS 0.6%CVE-2023-26026MEDIUMIBM Planning Analytics Cartridge for Cloud Pak for Data information disclosureEPSS 0.6%CVE-2026-84134CRITICALOther issue in the Profile Backup componentEPSS 0.6%CVE-2023-24959MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.6%CVE-2025-49664MEDIUMWindows User-Mode Driver Framework Host Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-27296MEDIUMDirectus version number disclosureEPSS 0.6%CVE-2024-29036MEDIUMSaleor Storefront session leak in cacheEPSS 0.6%CVE-2026-13697HIGHundici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesEPSS 0.6%