Fallos del tipo CWE-212

78 resultados

Divulgação de informações sensíveis

A aplicação expõe dados que não deveria (senhas, tokens, caminhos internos, versões de software) a usuários não autorizados, seja por erro de configuração, logging inadequado ou resposta de erro verbosa. O perigo está em dar ao atacante informações que facilitam exploração de outras vulnerabilidades ou comprometem a confidencialidade.

Ejemplo

Um servidor web retorna stack traces completos em páginas de erro, revelando caminhos absolutos do servidor e bibliotecas em uso; ou a aplicação exibe o token de sessão do usuário em logs do navegador acessíveis via JavaScript; ou uma API retorna mensagens de erro que confirmam quais usuários existem no sistema.

Cómo mitigar

Implemente tratamento genérico de erros (nunca exiba detalhes técnicos ao usuário final), revise logs e respostas da API para garantir que dados sensíveis não sejam registrados ou retornados, e use variáveis de ambiente para armazenar secrets em vez de hardcodá-los no código ou comentários.

CVE-2025-57757MEDIUMContao discloses information in the news moduleEPSS 0.3%CVE-2026-82069MEDIUMImproper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster RouterEPSS 0.3%CVE-2025-59955MEDIUMCoolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpointEPSS 0.3%CVE-2026-27640HIGHtfplan2md has Sensitive Value Exposure in Generated ReportsEPSS 0.3%CVE-2024-32028MEDIUMSensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCoreEPSS 0.3%CVE-2026-54421MEDIUMIn OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can returnEPSS 0.3%CVE-2024-29120MEDIUMApache StreamPark: Information leakage vulnerabilityEPSS 0.3%CVE-2026-78658MEDIUMIBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerabilityEPSS 0.3%CVE-2026-46657HIGHBludit's persistent authentication tokens not revoked upon account disablementEPSS 0.3%CVE-2025-62483MEDIUMZoom Clients - Improper Removal of Sensitive InformationEPSS 0.3%CVE-2026-39937HIGHGlobal vanishing does not completely remove user emailEPSS 0.3%CVE-2021-33082MEDIUMSensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and Intel(R) Optane(TM) SSD Products may allow EPSS 0.3%CVE-2021-33080MEDIUMExposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD anEPSS 0.3%CVE-2026-16104MEDIUMKeycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only adminsEPSS 0.3%CVE-2026-73440LOWSecurity Advisory 0178EPSS 0.3%CVE-2026-1732MEDIUMImproper Removal of Sensitive Information Before Storage or Transfer in GitLabEPSS 0.3%CVE-2026-42186LOWOpenBao's Namespace Deletion May Not Delete Data ProperlyEPSS 0.2%CVE-2026-85094HIGHThe Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat EPSS 0.2%CVE-2026-27892MEDIUMFacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/DownloadEPSS 0.2%CVE-2026-43824HIGHIn Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.EPSS 0.2%