Fallos del tipo CWE-201

411 resultados

Inserção de informações sensíveis em dados enviados

A aplicação inclui dados sensíveis (senhas, tokens, chaves, PII) em comunicações que não deveriam contê-los — logs, requisições HTTP, mensagens de erro, caches ou tráfego de rede. O risco é esses dados serem interceptados, armazenados ou expostos em canais menos protegidos.

Ejemplo

Um sistema registra credenciais de banco de dados completas em logs de debug que ficam acessíveis a analistas, ou uma API retorna o token de autenticação do usuário em resposta de erro exibida ao cliente. Outro caso comum: enviar senhas em parâmetros de URL (no histórico do navegador e logs de servidor).

Cómo mitigar

Identifique quais dados são sensíveis e nunca os inclua em logs, mensagens de erro, caches ou respostas da API. Use máscara (ex: exibir apenas últimos 4 dígitos) quando necessário exibir, e sanitize outputs antes de enviar ao cliente. Revise regularmente logs e históricos de requisição.

CVE-2022-28224MEDIUMCalico and Calico Enterprise may be vulnerable to route hijacking with the floating IP featureEPSS 0.6%CVE-2023-4002MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%CVE-2023-1975HIGHInsertion of Sensitive Information Into Sent Data in answerdev/answerEPSS 0.6%CVE-2024-53804HIGHWordPress WP Mailster plugin <= 1.8.16.0 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-34812MEDIUMWordPress ShopBuilder plugin <= 2.1.8 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-34556MEDIUMWordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.5.4 - Sensitive Data Exposure via Exported File vulnerabilityEPSS 0.6%CVE-2026-39912CRITICALv2board / Xboard Authentication Token Exposure via loginWithMailLinkEPSS 0.6%CVE-2023-3102MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%CVE-2024-35189MEDIUMSensitive Data Disclosure Vulnerability in Connection Configuration Endpoints in FidesEPSS 0.6%CVE-2022-23488MEDIUMBigBlueButton vulnerable to Insertion of Sensitive Information Into Sent DataEPSS 0.6%CVE-2023-6916HIGHInformation disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1EPSS 0.6%CVE-2025-59509MEDIUMWindows Speech Recognition Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-2620MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2024-25148MEDIUMIn Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, anEPSS 0.5%CVE-2024-56300HIGHWordPress Post/Page Copying Tool plugin <= 2.0.0 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-46665LOWAn insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in EPSS 0.5%CVE-2026-82209HIGHdomain-scoped PSL domain cookieEPSS 0.5%CVE-2023-1825LOWInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2021-1425MEDIUMCisco Cisco Email Security Appliance and Content Security Management Appliance Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-28173MEDIUMIn JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosedEPSS 0.5%