Fallos del tipo CWE-204

188 resultados

Vazamento de informações por resposta diferenciada

A aplicação entrega respostas distintas (tempo de processamento, mensagens de erro, status HTTP, conteúdo) dependendo de estados internos ou dados sensíveis, permitindo que um atacante deduza informações que deveria estar ocultas. Por exemplo, responder "usuário não encontrado" em vez de "senha incorreta" revela quais contas existem no sistema.

Ejemplo

Um serviço de autenticação retorna erro diferente se a senha está errada ("Acesso negado") versus se o e-mail não existe no banco ("E-mail não registrado"). Um atacante lista e-mails válidos simplesmente testando combinações. Ou um endpoint que demora 500ms para usuários autenticados mas 50ms para tokens inválidos, vazando informações via timing.

Cómo mitigar

Padronize todas as respostas de erro relevantes (mesmo mensagem, mesmo código HTTP, mesmo tempo de processamento). Use respostas genéricas ("Credenciais inválidas" em vez de especificar o motivo) e implemente rate limiting para dificultar enumeração. Valide que dados sensíveis nunca vazam em headers, timing ou logs públicos.

CVE-2021-36201MEDIUMCCURE Observable Response DiscrepancyEPSS 0.6%CVE-2024-40627MEDIUMOpaMiddleware does not filter HTTP OPTIONS requestsEPSS 0.6%CVE-2023-41885MEDIUMPiccolo's current `BaseUser.login` implementation is vulnerable to time based user enumerationEPSS 0.6%CVE-2023-32346MEDIUM Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function reEPSS 0.5%CVE-2025-24980MEDIUMPimcore Admin Classic Bundle allows user enumerationEPSS 0.5%CVE-2025-31124MEDIUMZitadel allows User Enumeration by loginname attribute normalizationEPSS 0.5%CVE-2023-23584MEDIUM An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence oEPSS 0.5%CVE-2025-54834MEDIUMOPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumerationEPSS 0.5%CVE-2024-1145MEDIUMObservable Response Discrepancy at Alma Devklan BlogEPSS 0.5%CVE-2023-28412MEDIUM When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of dEPSS 0.5%CVE-2023-27283MEDIUMIBM Aspera Orchestrator information disclosureEPSS 0.5%CVE-2023-38362MEDIUMIBM CICS TX information disclosureEPSS 0.5%CVE-2026-66002MEDIUMFrappe: User Enumeration via PDDREPSS 0.5%CVE-2024-51447MEDIUMA vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of tEPSS 0.5%CVE-2021-20556MEDIUMIBM Cognos Controller information disclosureEPSS 0.5%CVE-2023-37831An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentEPSS 0.5%CVE-2023-27464MEDIUMA vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix EPSS 0.5%CVE-2025-40806MEDIUMA vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeratioEPSS 0.5%CVE-2023-4095MEDIUMUser enumeration vulnerability in Fujitsu Arconte ÁureaEPSS 0.5%CVE-2025-30280MEDIUMA vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), MendiEPSS 0.5%