Fallos del tipo CWE-200

4927 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-45803MEDIUMRequest body not stripped after redirect in urllib3EPSS 0.5%CVE-2023-47222CRITICALMedia Streaming add-onEPSS 0.5%CVE-2024-5067MEDIUMExposure of Sensitive Information to an Unauthorized Actor in GitLabEPSS 0.5%CVE-2026-47136MEDIUMRustFS: Unauthenticated RustFS console license endpoint exposes license metadataEPSS 0.5%CVE-2025-63958CRITICALMILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authEPSS 0.5%CVE-2024-8777HIGHThe SYSCOM Group OMFLOW - Information LeakageEPSS 0.5%CVE-2024-5133CRITICALAccount Takeover via Exposed Recovery Token in lunary-ai/lunaryEPSS 0.5%CVE-2026-53647MEDIUMFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointEPSS 0.5%CVE-2023-25965MEDIUMWordPress Upload Resume plugin <= 1.2.0 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-37113CRITICALWordPress WishList Member X plugin < 3.26.7 - Unauthenticated Database Backup Download vulnerabilityEPSS 0.5%CVE-2021-3031MEDIUMPAN-OS: Information exposure in Ethernet data frame construction (Etherleak)EPSS 0.5%CVE-2025-12616MEDIUMPHPGurukul News Portal settings.py insertion of sensitive information into debugging codeEPSS 0.5%CVE-2026-9612MEDIUMWhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLsEPSS 0.5%CVE-2026-37453HIGHInsecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via EPSS 0.5%CVE-2023-27877MEDIUMIBM Planning Analytics Cartridge for Cloud Pak for Data information disclosureEPSS 0.5%CVE-2023-22876MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.5%CVE-2024-57716HIGHAn issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.EPSS 0.5%CVE-2023-35898MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.5%CVE-2026-54659MEDIUMPagy I18n locale option is not validated before being used in a file pathEPSS 0.5%CVE-2026-50222HIGHApache CloudStack: Improper access control in Userdata reference APIsEPSS 0.5%