Fallos del tipo CWE-200

4927 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-22611HIGHA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specEPSS 0.6%CVE-2026-92708HIGHdevalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node BuffersEPSS 0.6%CVE-2025-5334HIGHExposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows EPSS 0.6%CVE-2020-29010MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay EPSS 0.6%CVE-2026-49984HIGHKestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)EPSS 0.6%CVE-2024-11089MEDIUMAnonymous Restricted Content <= 1.6.5 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.6%CVE-2022-41917MEDIUMIncorrect Error Handling Allowed Partial File Reads Over REST API in OpenSearchEPSS 0.6%CVE-2025-11443MEDIUMJhumanJ OpnForm Forgotten Password email information exposureEPSS 0.6%CVE-2023-38729MEDIUMIBM Db2 information disclosureEPSS 0.6%CVE-2022-46257—Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository namesEPSS 0.6%CVE-2026-40245HIGHFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationEPSS 0.6%CVE-2026-79323HIGHInformation disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 EPSS 0.6%CVE-2026-8198MEDIUMActivity Logs, User Activity Tracking, Multisite Activity Log from Logtivity <= 3.3.6 - Unauthenticated Information Disclosure via REST APIEPSS 0.6%CVE-2024-21205MEDIUMVulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version thaEPSS 0.6%CVE-2026-42880CRITICALArgoCD ServerSideDiff is vulnerable to Kubernetes Secret ExtractionEPSS 0.6%CVE-2026-40166HIGHauthentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/EPSS 0.6%CVE-2024-2541MEDIUMPopup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV FileEPSS 0.6%CVE-2022-36075LOWFile list exposure in Nextcloud Files Access ControlEPSS 0.6%CVE-2026-52837MEDIUMEasy!Appointments has unauthenticated customer PII disclosure on booking reschedule pageEPSS 0.6%CVE-2026-55485HIGHPiccolo Admin: Privilege escalation - admin to superuser via session-token disclosure in GET /api/tables/sessions/.EPSS 0.6%