Fallos del tipo CWE-201

411 resultados

Inserção de informações sensíveis em dados enviados

A aplicação inclui dados sensíveis (senhas, tokens, chaves, PII) em comunicações que não deveriam contê-los — logs, requisições HTTP, mensagens de erro, caches ou tráfego de rede. O risco é esses dados serem interceptados, armazenados ou expostos em canais menos protegidos.

Ejemplo

Um sistema registra credenciais de banco de dados completas em logs de debug que ficam acessíveis a analistas, ou uma API retorna o token de autenticação do usuário em resposta de erro exibida ao cliente. Outro caso comum: enviar senhas em parâmetros de URL (no histórico do navegador e logs de servidor).

Cómo mitigar

Identifique quais dados são sensíveis e nunca os inclua em logs, mensagens de erro, caches ou respostas da API. Use máscara (ex: exibir apenas últimos 4 dígitos) quando necessário exibir, e sanitize outputs antes de enviar ao cliente. Revise regularmente logs e históricos de requisição.

CVE-2025-47541HIGHWordPress Mail Mint plugin <= 1.17.7 - Sensitive Data Exposure VulnerabilityEPSS 0.5%CVE-2023-3399HIGHInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-31134MEDIUMFreshRSS vulnerable to directory enumeration via ext.phpEPSS 0.4%CVE-2024-49235HIGHWordPress Contact Forms, Live Support, CRM, Video Messages plugin <= 1.10.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-49584HIGHXWiki makes title of inaccessible pages available through the class property values REST APIEPSS 0.4%CVE-2026-41181MEDIUMTraefik: Errors middleware forwards Authorization and Cookie headers to separate error page serviceEPSS 0.4%CVE-2024-26270MEDIUMThe Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 EPSS 0.4%CVE-2025-22303MEDIUMWordPress WP Mailster plugin <= 1.8.17.0 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-25150MEDIUMInformation disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and LiferayEPSS 0.4%CVE-2026-13437MEDIUMInsertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticatEPSS 0.4%CVE-2026-42997HIGHAn issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be senEPSS 0.4%CVE-2026-54171MEDIUMExcon: redact additional sensitive/risky headers when following redirectsEPSS 0.4%CVE-2025-48749CRITICALNetwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent DaEPSS 0.4%CVE-2025-48934MEDIUMDeno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesEPSS 0.4%CVE-2024-38787HIGHWordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerabilityEPSS 0.4%CVE-2026-6267HIGHInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.4%CVE-2025-64502MEDIUMParse Server allows public `explain` queries which may expose sensitive database performance information and schema detailsEPSS 0.4%CVE-2024-39315MEDIUMPomerium exposed OAuth2 access and ID tokens in user info endpoint responseEPSS 0.4%CVE-2026-7189HIGHSensitive Data Exposure in Proliz's OBSEPSS 0.4%CVE-2026-7488HIGHSensitive Data Exposure in IKAS Technologies' E-CommerceEPSS 0.4%