Fallos del tipo CWE-200

4933 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-48799HIGHAn issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware upEPSS 0.5%CVE-2024-48798HIGHAn issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmwaEPSS 0.5%CVE-2024-48796HIGHAn issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.EPSS 0.5%CVE-2024-3706MEDIUMExposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenGnsysEPSS 0.5%CVE-2022-39378MEDIUMDisplaying user badges can leak topic titles to users that have no access to the topicEPSS 0.5%CVE-2022-43868MEDIUMIBM Security Verify Access information disclosureEPSS 0.5%CVE-2021-26333—AMD Chipset Driver Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-34785HIGHRack: Local file inclusion in `Rack::Static` via URL Prefix MatchingEPSS 0.5%CVE-2024-51163HIGHA Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive EPSS 0.5%CVE-2026-11431HIGHPath Traversal in Altium Projects Service Allows Arbitrary File ReadEPSS 0.5%CVE-2024-4159MEDIUMProtection mechanismsEPSS 0.5%CVE-2026-32865CRITICALOPEXUS eComplaint and eCase insecure password resetEPSS 0.5%CVE-2025-0403MEDIUM1902756969 reggie Phone Number Validation sendMsg information disclosureEPSS 0.5%CVE-2022-40696LOWWordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2025-27615HIGHumatiGateway's UI publicly accessible in provided docker-compose fileEPSS 0.5%CVE-2024-12255MEDIUMAccept Stripe Payments Using Contact Form 7 <= 2.5 - Unauthenticated Information ExposureEPSS 0.5%CVE-2025-30353HIGHDirectus's webhook trigger flows can leak sensitive dataEPSS 0.5%CVE-2023-50705MEDIUMExposure of Sensitive Information to an Unauthorized Actor in EFACEC UC 500EEPSS 0.5%CVE-2023-2025MEDIUMExposure of Sensitive Information in OpenBlue Enterprise Manager Data CollectorEPSS 0.5%CVE-2026-52203HIGHAn issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.EPSS 0.5%