Fallos del tipo CWE-209

427 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

Quando a aplicação exibe mensagens de erro muito detalhadas ao usuário, revelando informações internas como caminhos de arquivo, versões de software, nomes de banco de dados ou stack traces completos. Um atacante usa essas informações para mapear a infraestrutura e identificar vulnerabilidades conhecidas.

Ejemplo

Um formulário de login retorna 'Erro: usuário admin não encontrado no banco de dados PostgreSQL v13.2' em vez de apenas 'Credenciais inválidas'. Ou uma exceção não tratada mostra o caminho completo /var/www/html/config.php e a linha exata do código que falhou, dando ao atacante um mapa detalhado da aplicação.

Cómo mitigar

Implemente mensagens genéricas para o usuário final ('Dados inválidos') e registre os detalhes técnicos apenas em logs internos que o usuário não acessa. Desative o modo debug em produção e configure tratamento de exceções customizado que nunca exponha stack traces, caminhos ou versões de componentes.

CVE-2024-13538MEDIUMBigBuy Dropshipping Connector for WooCommerce <= 2.0.0 - Unauthenticated Full Path DisclosuteEPSS 0.6%CVE-2023-46240HIGHCodeIgniter4 vulnerable to information disclosure when detailed error report is displayed in production environmentEPSS 0.6%CVE-2022-38107MEDIUMSensitive Data Disclosure VulnerabilityEPSS 0.6%CVE-2024-2009MEDIUMNway Pro Argument index.php ajax_login_submit_form information exposureEPSS 0.6%CVE-2024-35155MEDIUMIBM MQ information disclosureEPSS 0.6%CVE-2022-33930MEDIUMDell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit thiEPSS 0.6%CVE-2023-1210LOWGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.6%CVE-2025-9005MEDIUMmtons mblog register information exposureEPSS 0.6%CVE-2024-22646MEDIUMAn email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to gueEPSS 0.6%CVE-2024-54366MEDIUMWordPress Vimeography plugin <= 2.4.4 - Full Path Disclosure (FPD) vulnerabilityEPSS 0.6%CVE-2023-47152MEDIUMIBM Db2 information disclosureEPSS 0.6%CVE-2026-49365MEDIUMApache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clientsEPSS 0.6%CVE-2026-56139MEDIUMApache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clientsEPSS 0.6%CVE-2025-44203HIGHIn HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs EPSS 0.6%CVE-2023-48393MEDIUMKaifa Technology WebITR - Error Message LeakageEPSS 0.6%CVE-2024-25037MEDIUMIBM Cognos Controller information disclosureEPSS 0.6%CVE-2024-12380MEDIUMGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.6%CVE-2023-6944MEDIUMRhdh: catalog-import function leaks credentials to frontendEPSS 0.6%CVE-2024-6980CRITICALVerbose error handling issue in GravityZone Update Server proxy serviceEPSS 0.6%CVE-2023-3362MEDIUMGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.5%