Fallos del tipo CWE-201

411 resultados

Inserção de informações sensíveis em dados enviados

A aplicação inclui dados sensíveis (senhas, tokens, chaves, PII) em comunicações que não deveriam contê-los — logs, requisições HTTP, mensagens de erro, caches ou tráfego de rede. O risco é esses dados serem interceptados, armazenados ou expostos em canais menos protegidos.

Ejemplo

Um sistema registra credenciais de banco de dados completas em logs de debug que ficam acessíveis a analistas, ou uma API retorna o token de autenticação do usuário em resposta de erro exibida ao cliente. Outro caso comum: enviar senhas em parâmetros de URL (no histórico do navegador e logs de servidor).

Cómo mitigar

Identifique quais dados são sensíveis e nunca os inclua em logs, mensagens de erro, caches ou respostas da API. Use máscara (ex: exibir apenas últimos 4 dígitos) quando necessário exibir, e sanitize outputs antes de enviar ao cliente. Revise regularmente logs e históricos de requisição.

CVE-2020-37150HIGHEdimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password DisclosureEPSS 0.7%CVE-2025-62126MEDIUMWordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2023-48240CRITICALXWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryEPSS 0.7%CVE-2026-44487HIGHAxios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP AdapterEPSS 0.7%CVE-2025-59136MEDIUMWordPress Gerencianet Oficial plugin <= 3.1.3 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2026-80255HIGHsecure cookie attribute bypass with tabEPSS 0.7%CVE-2026-44486HIGHAxios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionEPSS 0.7%CVE-2022-45428LOWSome Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by seEPSS 0.7%CVE-2024-54309MEDIUMWordPress PostBox plugin <= 1.0.4 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2026-8924CRITICALtrailing dot domain super cookieEPSS 0.7%CVE-2025-66035HIGHAngular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLsEPSS 0.7%CVE-2023-28117HIGHSentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`EPSS 0.6%CVE-2025-48045HIGHMICI Network Co. Ltd. NetFax Server Default Administrator Credentials DisclosureEPSS 0.6%CVE-2024-50633NONEA Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted PEPSS 0.6%CVE-2023-3413MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%CVE-2026-32829HIGHlz4_flex: Decompression can leak information from uninitialized memory or reused output bufferEPSS 0.6%CVE-2025-23781HIGHWordPress WM Options Import Export plugin <= 1.0.1 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2025-66566HIGHyawkat LZ4 Java has a possible information leak in Java safe decompressorEPSS 0.6%CVE-2023-3299LOWNomad Caller ACL Token's Secret ID is Exposed to SentinelEPSS 0.6%CVE-2023-3949MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%