Fallos del tipo CWE-209

426 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

Quando a aplicação exibe mensagens de erro muito detalhadas ao usuário, revelando informações internas como caminhos de arquivo, versões de software, nomes de banco de dados ou stack traces completos. Um atacante usa essas informações para mapear a infraestrutura e identificar vulnerabilidades conhecidas.

Ejemplo

Um formulário de login retorna 'Erro: usuário admin não encontrado no banco de dados PostgreSQL v13.2' em vez de apenas 'Credenciais inválidas'. Ou uma exceção não tratada mostra o caminho completo /var/www/html/config.php e a linha exata do código que falhou, dando ao atacante um mapa detalhado da aplicação.

Cómo mitigar

Implemente mensagens genéricas para o usuário final ('Dados inválidos') e registre os detalhes técnicos apenas em logs internos que o usuário não acessa. Desative o modo debug em produção e configure tratamento de exceções customizado que nunca exponha stack traces, caminhos ou versões de componentes.

CVE-2025-65995MEDIUMApache Airflow: Disclosure of secrets to UI via kwargsEPSS 0.8%CVE-2015-10012LOWsumocoders FrameworkUserBundle login.html.twig information exposureEPSS 0.8%CVE-2023-23837HIGHNo Exception Handling Vulnerability: Database Performance Analyzer (DPA) 2023.1EPSS 0.8%CVE-2023-31048MEDIUMThe OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.EPSS 0.8%CVE-2021-33711A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versionEPSS 0.8%CVE-2022-22363MEDIUMIBM Cognos Controller information disclosureEPSS 0.8%CVE-2021-32775HIGHAny user can see any fields (including mailbox password) with GroupBy DashletEPSS 0.8%CVE-2022-31229CRITICALDell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator could potentially exploiEPSS 0.8%CVE-2020-1717A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.EPSS 0.8%CVE-2023-29193HIGHSpiceDB binding metrics port to untrusted networks and can leak command-line flagsEPSS 0.8%CVE-2021-31339A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an EPSS 0.8%CVE-2022-22760MEDIUMWhen importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> respEPSS 0.8%CVE-2023-26052LOWSaleor is vulnerable to unauthenticated information disclosure via Python exceptionsEPSS 0.8%CVE-2023-47703MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.8%CVE-2018-19947MEDIUMThe vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disEPSS 0.8%CVE-2019-16768LOWInternal exception message exposure for login action in SyliusEPSS 0.7%CVE-2023-33835MEDIUMIBM Security Verify Information Queue information disclosureEPSS 0.7%CVE-2020-5026MEDIUMIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitEPSS 0.7%CVE-2018-17891Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream seEPSS 0.7%CVE-2021-31341Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server anEPSS 0.7%