Fallos del tipo CWE-209

432 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

Quando a aplicação exibe mensagens de erro muito detalhadas ao usuário, revelando informações internas como caminhos de arquivo, versões de software, nomes de banco de dados ou stack traces completos. Um atacante usa essas informações para mapear a infraestrutura e identificar vulnerabilidades conhecidas.

Ejemplo

Um formulário de login retorna 'Erro: usuário admin não encontrado no banco de dados PostgreSQL v13.2' em vez de apenas 'Credenciais inválidas'. Ou uma exceção não tratada mostra o caminho completo /var/www/html/config.php e a linha exata do código que falhou, dando ao atacante um mapa detalhado da aplicação.

Cómo mitigar

Implemente mensagens genéricas para o usuário final ('Dados inválidos') e registre os detalhes técnicos apenas em logs internos que o usuário não acessa. Desative o modo debug em produção e configure tratamento de exceções customizado que nunca exponha stack traces, caminhos ou versões de componentes.

CVE-2025-12365MEDIUMError Messages Wrapped In HTTP HeaderEPSS 0.2%CVE-2025-43777MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.QEPSS 0.2%CVE-2023-50355LOWHCL Sametime is impacted by generation of error messages containing sensitive informationEPSS 0.2%CVE-2021-1546MEDIUMCisco SD-WAN Software Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-59016MEDIUMInformation Disclosure via File Abstraction LayerEPSS 0.2%CVE-2021-47161MEDIUMspi: spi-fsl-dspi: Fix a resource leak in an error handling pathEPSS 0.2%CVE-2026-3259HIGHSensitive Data Disclosure in BigQuery via Materialized View Error MessagesEPSS 0.2%CVE-2026-73844LOWCKAN MCP Server: Information disclosure via verbose error reflectionEPSS 0.2%CVE-2025-54562MEDIUMA vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical InformatioEPSS 0.2%CVE-2026-1248MEDIUMIBM Business Automation Workflow information leakEPSS 0.2%CVE-2026-47775MEDIUMEnvoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie DecryptionEPSS 0.2%CVE-2023-31429MEDIUMMultiple commands print sensitive information in the terminalEPSS 0.2%CVE-2026-5511MEDIUMInformation Disclosure via Diagnostic Interface Due to Improper Input Validation on TP-Link's Archer AX72EPSS 0.2%CVE-2025-43776MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 202EPSS 0.2%CVE-2026-56620MEDIUMHCL BigFix Mobile is vulnerable to information disclosureEPSS 0.2%CVE-2025-36437MEDIUMIBM Planning Analytics Local is vulnerable to disclosing sensitive informationEPSS 0.2%CVE-2025-66594MEDIUMA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed on the error page. EPSS 0.2%CVE-2023-34339LOWIn JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's messageEPSS 0.2%CVE-2024-52897MEDIUMIBM MQ information disclosureEPSS 0.2%CVE-2024-3454LOWIn-Fabric Matter Cluster Attribute DisclosureEPSS 0.2%