Fallos del tipo CWE-203

350 resultados

Discrepância Observável em Respostas

A aplicação revela informações sensíveis através de diferenças detectáveis em seu comportamento, tempo de resposta ou mensagens de erro — por exemplo, retornando erros diferentes para usuário inexistente vs. senha incorreta. Um atacante pode explorar essas pistas para inferir dados confidenciais sem acesso direto.

Ejemplo

Um sistema de login que responde 'Usuário não encontrado' em 100ms, mas 'Senha incorreta' em 500ms (após validação). Um invasor enumera contas válidas medindo latência, ou identifica emails registrados pela velocidade da resposta.

Cómo mitigar

Padronize respostas de erro (mesma mensagem genérica), normalize tempos de execução com delays constantes, e evite vazar informações estruturais (ex: 'este email já existe'). Auditoria de logs e timestamps também revelar quem tentou enumerar dados sensíveis.

CVE-2021-34576MEDIUMObservable discrepancy in Kaden PICOFLUX AiR leaks water consumptionEPSS 0.4%CVE-2026-26185MEDIUMDirectus Affected by User Enumeration via Password Reset Timing AttackEPSS 0.4%CVE-2026-79016MEDIUMObservable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTEPSS 0.4%CVE-2026-56327MEDIUMCapgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPCEPSS 0.4%CVE-2022-50800MEDIUMH3C SSL VPN n/a Username Enumeration via Login Script Credential VerificationEPSS 0.4%CVE-2026-56296MEDIUMCap-go - App Existence Oracle via Unauthenticated transfer_app RPCEPSS 0.4%CVE-2026-55555LOWDompdf: File existence oracle via font-face stylesheet declarationEPSS 0.4%CVE-2023-46739MEDIUMTiming attack can leak user passwordsEPSS 0.4%CVE-2023-53943MEDIUMGLPI 9.5.7 Username Enumeration Vulnerability via Lost Password EndpointEPSS 0.4%CVE-2026-87478MEDIUMObservable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a cEPSS 0.4%CVE-2024-1544MEDIUMECDSA nonce bias caused by truncationEPSS 0.3%CVE-2026-26895MEDIUMUser enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the plEPSS 0.3%CVE-2023-32694MEDIUMNon-constant time HMAC comparison in Adyen plugin in SaleorEPSS 0.3%CVE-2024-41880MEDIUMIn veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and pEPSS 0.3%CVE-2025-6011LOWTiming Side-Channel in Vault’s Userpass Auth MethodEPSS 0.3%CVE-2025-52576MEDIUMKanboard vulnerable to Username Enumeration via Login Behavior and Bruteforce Protection BypassEPSS 0.3%CVE-2024-45678MEDIUMYubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extracEPSS 0.3%CVE-2025-64749MEDIUMDirectus Vulnerable to Information Leakage in Existing CollectionsEPSS 0.3%CVE-2025-0361MEDIUMDuring an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration frEPSS 0.3%CVE-2026-79030MEDIUMObservable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a cEPSS 0.3%