Fallos del tipo CWE-200

4898 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-2462MEDIUMTransposh WordPress Translation <= 1.0.9.6 - Sensitive Information DisclosureEPSS 3.7%CVE-2016-6548—Zizai Tech Nut mobile application makes requests using HTTP, which includes the users session tokenEPSS 3.7%CVE-2025-49741HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 3.6%CVE-2019-5016CRITICALAn exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functioEPSS 3.6%CVE-2018-15919MEDIUMRemotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a targEPSS 3.6%CVE-2020-8169—curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over thEPSS 3.5%CVE-2018-5407—Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel EPSS 3.4%CVE-2018-0425—Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure VulnerabilityEPSS 3.4%CVE-2026-22240CRITICALPlaintext Passwords Vulnerability in BLUVOYIXEPSS 3.4%CVE-2017-7520—OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-iEPSS 3.4%CVE-2014-2356—Innominate mGuard Exposure of Sensitive Information to an Unauthorized ActorEPSS 3.4%CVE-2025-59434CRITICALCritical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript FunctionEPSS 3.4%CVE-2018-0442HIGHCisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points Protocol Information Disclosure VulnerabilityEPSS 3.3%CVE-2024-50338HIGHCarriage-return character in remote URL allows malicious repository to leak credentials in Git Credential ManagerEPSS 3.2%CVE-1999-0468HIGHInternet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.EPSS 3.2%CVE-2017-6752—A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remoteEPSS 3.2%CVE-2025-55976HIGHIntelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local netwEPSS 3.2%CVE-2022-27775HIGHAn information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connectEPSS 3.2%CVE-2023-34092HIGHVite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)EPSS 3.1%CVE-2018-10911MEDIUMA flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaEPSS 3.1%