Fallos del tipo CWE-203

350 resultados

Discrepância Observável em Respostas

A aplicação revela informações sensíveis através de diferenças detectáveis em seu comportamento, tempo de resposta ou mensagens de erro — por exemplo, retornando erros diferentes para usuário inexistente vs. senha incorreta. Um atacante pode explorar essas pistas para inferir dados confidenciais sem acesso direto.

Ejemplo

Um sistema de login que responde 'Usuário não encontrado' em 100ms, mas 'Senha incorreta' em 500ms (após validação). Um invasor enumera contas válidas medindo latência, ou identifica emails registrados pela velocidade da resposta.

Cómo mitigar

Padronize respostas de erro (mesma mensagem genérica), normalize tempos de execução com delays constantes, e evite vazar informações estruturais (ex: 'este email já existe'). Auditoria de logs e timestamps também revelar quem tentou enumerar dados sensíveis.

CVE-2026-21484MEDIUMAnythingLLM Vulnerable to Username Enumeration w/ Password RecoveryEPSS 0.8%CVE-2023-33741HIGHMacrovideo v380pro v1.4.97 shares the device id and password when sharing the device.EPSS 0.8%CVE-2023-40021MEDIUMTiming Attack Reveals CSRF Tokens in oppiaEPSS 0.8%CVE-2023-25741MEDIUMWhen dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused EPSS 0.8%CVE-2023-51437HIGHApache Pulsar: Timing attack in SASL token signature verificationEPSS 0.8%CVE-2020-1685MEDIUMJunos OS: EX4600, QFX5K Series: Stateless firewall filter matching 'user-vlan-id' will cause incomplete discard actionEPSS 0.8%CVE-2024-48644MEDIUMAccounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remoteEPSS 0.8%CVE-2024-13028MEDIUMAntabot White-Jotter login observable response discrepancyEPSS 0.7%CVE-2023-29850HIGHSENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain inforEPSS 0.7%CVE-2024-5690MEDIUMBy monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's EPSS 0.7%CVE-2023-50708MEDIUMyii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementationEPSS 0.7%CVE-2021-4286LOWcocagne pysrp _ctsrp.py calculate_x information exposureEPSS 0.7%CVE-2023-34878HIGHAn issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-hEPSS 0.7%CVE-2022-47952LOWlxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protecEPSS 0.7%CVE-2024-37880HIGHThe Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timEPSS 0.7%CVE-2022-43411MEDIUMJenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhooEPSS 0.7%CVE-2022-45403MEDIUMService Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media cEPSS 0.7%CVE-2024-10463HIGHVideo frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, FirefEPSS 0.7%CVE-2022-20940MEDIUMA vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain EPSS 0.7%CVE-2025-41252HIGHUsername enumeration vulnerabilityEPSS 0.7%