Fallos del tipo CWE-203

350 resultados

Discrepância Observável em Respostas

A aplicação revela informações sensíveis através de diferenças detectáveis em seu comportamento, tempo de resposta ou mensagens de erro — por exemplo, retornando erros diferentes para usuário inexistente vs. senha incorreta. Um atacante pode explorar essas pistas para inferir dados confidenciais sem acesso direto.

Ejemplo

Um sistema de login que responde 'Usuário não encontrado' em 100ms, mas 'Senha incorreta' em 500ms (após validação). Um invasor enumera contas válidas medindo latência, ou identifica emails registrados pela velocidade da resposta.

Cómo mitigar

Padronize respostas de erro (mesma mensagem genérica), normalize tempos de execução com delays constantes, e evite vazar informações estruturais (ex: 'este email já existe'). Auditoria de logs e timestamps também revelar quem tentou enumerar dados sensíveis.

CVE-2026-79028MEDIUMObservable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crEPSS 0.3%CVE-2026-53933MEDIUMMaravel-Framework Vulnerable to Side-Channel Information Disclosure (Error Oracle) via Dynamic Route FuzzingEPSS 0.3%CVE-2026-78617MEDIUMWatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate LimitingEPSS 0.3%CVE-2025-11145HIGHUser Enumeration in CBK Soft's enVisionEPSS 0.3%CVE-2025-40732HIGHUser enumeration vulnerability in Daily Expense ManagerEPSS 0.3%CVE-2023-5872MEDIUMWago: Vulnerability in Smart Designer Web-ApplicationEPSS 0.3%CVE-2025-6056MEDIUMTiming difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackeEPSS 0.3%CVE-2026-33429MEDIUMParse Server: Protected field change detection oracle via LiveQuery watch parameterEPSS 0.3%CVE-2023-28200MEDIUMA validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, EPSS 0.3%CVE-2024-47057MEDIUMUser name enumeration possible due to response time difference on password reset formEPSS 0.3%CVE-2026-59341MEDIUMSealed Secrets: decryption oracle via Go template injection in unauthenticated controller endpointsEPSS 0.3%CVE-2026-23937MEDIUMHost PSK extraction in Zabbix APIEPSS 0.3%CVE-2025-47872MEDIUMEG4 Electronics EG4 Inverters Observable DiscrepancyEPSS 0.3%CVE-2025-56423MEDIUMAn issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitEPSS 0.3%CVE-2024-54002MEDIUMDependency-Track allows enumeration of managed users via /api/v1/user/login endpointEPSS 0.3%CVE-2025-59702HIGHEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.3%CVE-2025-10890CRITICALSide-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crEPSS 0.3%CVE-2025-43751MEDIUMUser enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 202EPSS 0.3%CVE-2026-56319MEDIUMCapgo - App Existence Oracle via GET /statistics/app/:app_idEPSS 0.3%CVE-2023-38327MEDIUMAn issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unautEPSS 0.3%