Fallos del tipo CWE-212

78 resultados

Divulgação de informações sensíveis

A aplicação expõe dados que não deveria (senhas, tokens, caminhos internos, versões de software) a usuários não autorizados, seja por erro de configuração, logging inadequado ou resposta de erro verbosa. O perigo está em dar ao atacante informações que facilitam exploração de outras vulnerabilidades ou comprometem a confidencialidade.

Ejemplo

Um servidor web retorna stack traces completos em páginas de erro, revelando caminhos absolutos do servidor e bibliotecas em uso; ou a aplicação exibe o token de sessão do usuário em logs do navegador acessíveis via JavaScript; ou uma API retorna mensagens de erro que confirmam quais usuários existem no sistema.

Cómo mitigar

Implemente tratamento genérico de erros (nunca exiba detalhes técnicos ao usuário final), revise logs e respostas da API para garantir que dados sensíveis não sejam registrados ou retornados, e use variáveis de ambiente para armazenar secrets em vez de hardcodá-los no código ou comentários.

CVE-2026-62900MEDIUM.NET Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-31493MEDIUMAn improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 anEPSS 0.5%CVE-2026-45737MEDIUMArgo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotationsEPSS 0.5%CVE-2026-42880CRITICALArgoCD ServerSideDiff is vulnerable to Kubernetes Secret ExtractionEPSS 0.5%CVE-2025-27221LOWIn the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication crEPSS 0.5%CVE-2024-6055MEDIUMImproper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on WinEPSS 0.5%CVE-2026-40895MEDIUMfollow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect TargetsEPSS 0.5%CVE-2025-68131MEDIUMCBORDecoder reuse can leak shareable values across decode callsEPSS 0.5%CVE-2026-20928MEDIUMWindows Recovery Environment Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2025-53886MEDIUMDirectus doesn't redact tokens in Flow logsEPSS 0.4%CVE-2025-14267MEDIUMUnintended temporary cached data included in a structure only copy intended to be empty of dataEPSS 0.4%CVE-2024-41156LOWProfile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers vaEPSS 0.4%CVE-2025-58049MEDIUMXWiki PDF export jobs store sensitive cookies unencrypted in job statusesEPSS 0.4%CVE-2024-43384HIGHPhoenix Contact: Improper removal of sensitive information in MGUARD productsEPSS 0.3%CVE-2023-52376HIGHInformation management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.3%CVE-2026-43528HIGHOpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig AliasesEPSS 0.3%CVE-2020-25635MEDIUMA flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is compleEPSS 0.3%CVE-2025-48708MEDIUMgs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A createEPSS 0.3%CVE-2024-56353MEDIUMIn JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookiesEPSS 0.3%CVE-2022-23605MEDIUMExpired Ephemeral Messages not reliably removed in wire-webappEPSS 0.3%