Fallos del tipo CWE-209

427 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

Quando a aplicação exibe mensagens de erro muito detalhadas ao usuário, revelando informações internas como caminhos de arquivo, versões de software, nomes de banco de dados ou stack traces completos. Um atacante usa essas informações para mapear a infraestrutura e identificar vulnerabilidades conhecidas.

Ejemplo

Um formulário de login retorna 'Erro: usuário admin não encontrado no banco de dados PostgreSQL v13.2' em vez de apenas 'Credenciais inválidas'. Ou uma exceção não tratada mostra o caminho completo /var/www/html/config.php e a linha exata do código que falhou, dando ao atacante um mapa detalhado da aplicação.

Cómo mitigar

Implemente mensagens genéricas para o usuário final ('Dados inválidos') e registre os detalhes técnicos apenas em logs internos que o usuário não acessa. Desative o modo debug em produção e configure tratamento de exceções customizado que nunca exponha stack traces, caminhos ou versões de componentes.

CVE-2022-31023MEDIUMDev error stack trace leaking into prod in Play FrameworkEPSS 1.3%CVE-2022-31124HIGHPossible leak of key's raw field if declared length is incorrect in openssh_key_parserEPSS 1.3%CVE-2017-7551389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different returEPSS 1.2%CVE-2020-5274MEDIUMExceptions displayed in non-debug configurations in SymfonyEPSS 1.2%CVE-2021-3393An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but EPSS 1.2%CVE-2019-5483Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.EPSS 1.2%CVE-2020-25633MEDIUMA flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentiaEPSS 1.2%CVE-2022-0504MEDIUMGeneration of Error Message Containing Sensitive Information in microweber/microweberEPSS 1.2%CVE-2021-26726HIGHRemote code execution in Valmet DNA before Collection 2021EPSS 1.1%CVE-2019-11252MEDIUMCredential leakage when failing to mountEPSS 1.1%CVE-2023-39264MEDIUMApache Superset: Stack traces enabled by defaultEPSS 1.1%CVE-2020-15132MEDIUMReset Password / Login vulnerability in SuluEPSS 1.1%CVE-2020-8213An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid uEPSS 1.1%CVE-2019-19342MEDIUMA flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password containEPSS 1.1%CVE-2019-3756MEDIUMRSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend databasEPSS 1.1%CVE-2021-32937HIGHMDT AutoSave Generation of Error Message Containing Sensitive InformationEPSS 1.1%CVE-2023-35009MEDIUMIBM Cognos Analytics information disclosureEPSS 1.0%CVE-2023-31286MEDIUMAn issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks thEPSS 1.0%CVE-2021-42777CRITICALStimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any macEPSS 1.0%CVE-2022-0622MEDIUMGeneration of Error Message Containing Sensitive Information in snipe/snipe-itEPSS 1.0%