Fallos del tipo CWE-200

4927 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-25120MEDIUMImproper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3EPSS 0.5%CVE-2024-4266MEDIUMMetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2023-28421MEDIUMWordPress WordPress Email Marketing Plugin – WP Email Capture Plugin <= 3.10 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2023-2514MEDIUMDB username/password revealed in application logsEPSS 0.5%CVE-2025-2277HIGHExposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leEPSS 0.5%CVE-2026-55389HIGHdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`EPSS 0.5%CVE-2025-27785HIGHApplio allows arbitrary file read in train.py export_index functionEPSS 0.5%CVE-2024-32716MEDIUMWordPress StreamWeasels Twitch Integration plugin <= 1.7.8 - API Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.5%CVE-2024-37895MEDIUMAPI Key Leak in lobe-chatEPSS 0.5%CVE-2021-33146MEDIUMImproper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unautEPSS 0.5%CVE-2023-1775MEDIUMUnsanitized events sent over Websocket to regular users in a High Availability environmentEPSS 0.5%CVE-2026-59828MEDIUMDiscourse: Hidden post revisions leak through adjacent visible diffsEPSS 0.5%CVE-2024-23193MEDIUME-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of theEPSS 0.5%CVE-2022-39385MEDIUMUsers erroneously and transparently added to private messages in DiscourseEPSS 0.5%CVE-2026-55729HIGHLoytec LWEB802: Exposure of Sensitive Information in browser localStorageEPSS 0.5%CVE-2026-7166CRITICALMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.5%CVE-2024-5067MEDIUMExposure of Sensitive Information to an Unauthorized Actor in GitLabEPSS 0.5%CVE-2023-41786MEDIUMDatabase backups availability by low-privileged usersEPSS 0.5%CVE-2024-2632HIGHInformation Exposure Vulnerability on Meta4 HREPSS 0.5%