Fallos del tipo CWE-201

411 resultados

Inserção de informações sensíveis em dados enviados

A aplicação inclui dados sensíveis (senhas, tokens, chaves, PII) em comunicações que não deveriam contê-los — logs, requisições HTTP, mensagens de erro, caches ou tráfego de rede. O risco é esses dados serem interceptados, armazenados ou expostos em canais menos protegidos.

Ejemplo

Um sistema registra credenciais de banco de dados completas em logs de debug que ficam acessíveis a analistas, ou uma API retorna o token de autenticação do usuário em resposta de erro exibida ao cliente. Outro caso comum: enviar senhas em parâmetros de URL (no histórico do navegador e logs de servidor).

Cómo mitigar

Identifique quais dados são sensíveis e nunca os inclua em logs, mensagens de erro, caches ou respostas da API. Use máscara (ex: exibir apenas últimos 4 dígitos) quando necessário exibir, e sanitize outputs antes de enviar ao cliente. Revise regularmente logs e históricos de requisição.

CVE-2026-65812MEDIUMMicrosoft Teams for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-82837MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-66388MEDIUMApache Airflow: Secrets in rendered templates not redacted properly and exposed in the UIEPSS 0.5%CVE-2025-47775MEDIUMBullfrog's DNS over TCP bypasses domain filteringEPSS 0.5%CVE-2024-47569MEDIUMA insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, EPSS 0.5%CVE-2025-24858HIGHDevelocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hasheEPSS 0.5%CVE-2025-32594HIGHWordPress Simple WP Events plugin <= 1.8.17 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-32635HIGHWordPress Hive Support plugin <= 1.2.6 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-24639MEDIUMWordPress Korea for WooCommerce plugin <= 1.1.11 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-54649LOWpunchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-ToEPSS 0.5%CVE-2026-63481MEDIUMHurl: Cookies in Cookies section leak when redirecting to a different hostEPSS 0.5%CVE-2024-38372LOWUndici vulnerable to data leak when using response.arrayBuffer()EPSS 0.5%CVE-2020-14514MEDIUMTrailer Power Line Communications vulnerabilityEPSS 0.5%CVE-2026-1365MEDIUMInformation Disclosure in Sayax's OSOSEPSS 0.5%CVE-2024-5213MEDIUMExposure of Sensitive Information in mintplex-labs/anything-llmEPSS 0.5%CVE-2025-27244MEDIUMAssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitiveEPSS 0.5%CVE-2025-23774HIGHWordPress WPDB to Sql plugin <= 1.2 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2023-5831LOWInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-64407MEDIUMApache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.5%CVE-2026-34226HIGHHappy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookiesEPSS 0.5%