Fallos del tipo CWE-200

4927 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-45066MEDIUMWordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2022-36399MEDIUMWordPress Booked Plugin < 2.4.4 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-49211MEDIUMSymfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtilEPSS 0.5%CVE-2024-53859MEDIUMgo-gh `auth.TokenForHost` violates GitHub host security boundary within a codespaceEPSS 0.5%CVE-2026-25650MEDIUMMCP Salesforce Connector has arbitrary attribute access which leads to disclosure of Salesforce auth tokenEPSS 0.5%CVE-2026-76672CRITICALAuthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2024-23344MEDIUMTuleap's content of artifacts might be readable by unauthorized usersEPSS 0.5%CVE-2026-85717MEDIUMAsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect targetEPSS 0.5%CVE-2025-24239MEDIUMA downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to EPSS 0.5%CVE-2024-45792MEDIUMMantisBT vulnerable to information disclosure with user profilesEPSS 0.5%CVE-2018-16862MEDIUMA security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removaEPSS 0.5%CVE-2023-36539MEDIUMExposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.EPSS 0.5%CVE-2026-55390HIGHArbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gateEPSS 0.5%CVE-2025-24279MEDIUMThis issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. EPSS 0.5%CVE-2026-85588MEDIUMphpMyFAQ before 4.1.8 TOTP Secret Exposure via Data ExportEPSS 0.5%CVE-2023-52234MEDIUMWordPress Booster Elite for WooCommerce plugin < 7.1.2 - Auth. Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2023-46128MEDIUMExposure of hashed user passwords via REST API in NautobotEPSS 0.5%CVE-2023-23458MEDIUMSunell DVR – Exposure of Sensitive InformationEPSS 0.5%CVE-2023-52231MEDIUMWordPress Booster Plus for WooCommerce plugin < 7.1.2 - Auth. Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-23523MEDIUMWordPress Elementor Pro plugin <= 3.19.2 - Contributor+ Arbitrary User Meta Data Retrieval vulnerabilityEPSS 0.5%