Fallos del tipo CWE-209

429 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

Quando a aplicação exibe mensagens de erro muito detalhadas ao usuário, revelando informações internas como caminhos de arquivo, versões de software, nomes de banco de dados ou stack traces completos. Um atacante usa essas informações para mapear a infraestrutura e identificar vulnerabilidades conhecidas.

Ejemplo

Um formulário de login retorna 'Erro: usuário admin não encontrado no banco de dados PostgreSQL v13.2' em vez de apenas 'Credenciais inválidas'. Ou uma exceção não tratada mostra o caminho completo /var/www/html/config.php e a linha exata do código que falhou, dando ao atacante um mapa detalhado da aplicação.

Cómo mitigar

Implemente mensagens genéricas para o usuário final ('Dados inválidos') e registre os detalhes técnicos apenas em logs internos que o usuário não acessa. Desative o modo debug em produção e configure tratamento de exceções customizado que nunca exponha stack traces, caminhos ou versões de componentes.

CVE-2025-41076MEDIUMMultiple vulnerabilities in LimesurveyEPSS 0.3%CVE-2025-54791MEDIUMOMERO.web displays unecessary user information when requesting to reset the passwordEPSS 0.3%CVE-2026-2752MEDIUMNavtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to EPSS 0.3%CVE-2025-62397MEDIUMMoodle: router produces json instead of 404 error for invalid course idEPSS 0.3%CVE-2026-74879HIGHopenssl_encrypt before 1.4.0 Information Disclosure via /ready endpointEPSS 0.3%CVE-2025-0049LOWDisclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0EPSS 0.3%CVE-2026-73555MEDIUMvLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error MessagesEPSS 0.3%CVE-2025-61959MEDIUMVertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive InformationEPSS 0.3%CVE-2026-43873HIGHWWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone ServerEPSS 0.3%CVE-2026-55375MEDIUMcanto-saas-api: OAuth credentials exposed in URL query string and exception messagesEPSS 0.3%CVE-2026-28675MEDIUMOpenSift: Sensitive implementation details exposed via raw exception messages and token-returning endpointsEPSS 0.3%CVE-2026-41931MEDIUMVvveb < 1.0.8.2 Information Disclosure via Debug Exception HandlerEPSS 0.2%CVE-2026-47893HIGHSpring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketServiceEPSS 0.2%CVE-2022-22162HIGHJunos OS: A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged inEPSS 0.2%CVE-2026-1262MEDIUMIBM InfoSphere Information Server Information DisclosureEPSS 0.2%CVE-2026-9583MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposureEPSS 0.2%CVE-2026-44002MEDIUMvm2: Host File Path Disclosure via Stack Trace Information LeakEPSS 0.2%CVE-2025-31960MEDIUMHCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting moduleEPSS 0.2%CVE-2026-79777MEDIUMrclone before v1.75.0 Information Disclosure via RC APIEPSS 0.2%CVE-2025-62840HIGHHBS 3 Hybrid Backup SyncEPSS 0.2%