Fallos del tipo CWE-209

427 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

Quando a aplicação exibe mensagens de erro muito detalhadas ao usuário, revelando informações internas como caminhos de arquivo, versões de software, nomes de banco de dados ou stack traces completos. Um atacante usa essas informações para mapear a infraestrutura e identificar vulnerabilidades conhecidas.

Ejemplo

Um formulário de login retorna 'Erro: usuário admin não encontrado no banco de dados PostgreSQL v13.2' em vez de apenas 'Credenciais inválidas'. Ou uma exceção não tratada mostra o caminho completo /var/www/html/config.php e a linha exata do código que falhou, dando ao atacante um mapa detalhado da aplicação.

Cómo mitigar

Implemente mensagens genéricas para o usuário final ('Dados inválidos') e registre os detalhes técnicos apenas em logs internos que o usuário não acessa. Desative o modo debug em produção e configure tratamento de exceções customizado que nunca exponha stack traces, caminhos ou versões de componentes.

CVE-2025-52023MEDIUMA vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed erroEPSS 0.5%CVE-2025-52022MEDIUMA vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed EPSS 0.5%CVE-2022-4870MEDIUMIn affected versions of Octopus Deploy it is possible to discover network details via error messageEPSS 0.4%CVE-2024-35119MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2024-8571MEDIUMerjemin roll_cms views.py information exposureEPSS 0.4%CVE-2023-42475MEDIUMInformation Disclosure Vulnerability in Statutory ReportingEPSS 0.4%CVE-2024-39458LOWWhen Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnosticEPSS 0.4%CVE-2023-0833MEDIUMRed hat a-mq streams: component version with information disclosure flawEPSS 0.4%CVE-2022-4770MEDIUMHitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information EPSS 0.4%CVE-2022-4769MEDIUMHitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information EPSS 0.4%CVE-2025-4166MEDIUMVault May Include Sensitive Data in Error Logs When Using the KV v2 PluginEPSS 0.4%CVE-2024-45658LOWIBM Security Verify Access information disclosureEPSS 0.4%CVE-2023-23474LOWIBM Cognos Controller information disclosureEPSS 0.4%CVE-2022-0563MEDIUMA flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" envirEPSS 0.4%CVE-2024-52043MEDIUMUser enumeration in HubHubEPSS 0.4%CVE-2026-28786MEDIUMOpen WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`EPSS 0.4%CVE-2025-68110CRITICALChurchCRM discloses database information on error messageEPSS 0.4%CVE-2024-39751MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2026-22646MEDIUMCertain error messages returned by the application expose internal system details that should not be visible to end users, providing attackeEPSS 0.4%CVE-2024-13540MEDIUMWooODT Lite – Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path DsiclosureEPSS 0.4%