Fallos del tipo CWE-200

4927 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-25544HIGH Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote acceEPSS 0.5%CVE-2024-27120HIGHLocal File Inclusion in ComfortKey before version 24.1.2EPSS 0.5%CVE-2026-52101CRITICALAn issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadREPSS 0.5%CVE-2023-24567HIGH Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access toEPSS 0.5%CVE-2026-86284MEDIUMjaychouchannel Tourism-Management-System CommonController.java getOption information disclosureEPSS 0.5%CVE-2026-88874HIGHAVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication BypassEPSS 0.5%CVE-2025-24360MEDIUMOpening a malicious website while running a Nuxt dev server could allow read-only access to codeEPSS 0.5%CVE-2026-42047HIGHInngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methodsEPSS 0.5%CVE-2026-94413HIGHjshERP through 3.6 Password Hash Disclosure via /user/infoEPSS 0.5%CVE-2026-60264CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.5%CVE-2020-36835MEDIUMMigration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information DisclosureEPSS 0.5%CVE-2026-82306MEDIUMStarRocks Query Detail Endpoint Returns Every User's Query HistoryEPSS 0.5%CVE-2026-14161HIGHAdvantech|Hospital Queuing Management - Sensitive Data ExposureEPSS 0.5%CVE-2024-12426MEDIUMURL fetching can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.5%CVE-2024-30263HIGHThe PDF Viewer macro can be used to view PDF attachments with restricted accessEPSS 0.5%CVE-2026-47340MEDIUMApache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.EPSS 0.5%CVE-2026-4660HIGHGo-getter may allow to arbitrary filesystem reads through git operationsEPSS 0.5%CVE-2025-55683MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-25120MEDIUMImproper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3EPSS 0.5%CVE-2024-4266MEDIUMMetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information ExposureEPSS 0.5%