Fallos del tipo CWE-212

78 resultados

Divulgação de informações sensíveis

A aplicação expõe dados que não deveria (senhas, tokens, caminhos internos, versões de software) a usuários não autorizados, seja por erro de configuração, logging inadequado ou resposta de erro verbosa. O perigo está em dar ao atacante informações que facilitam exploração de outras vulnerabilidades ou comprometem a confidencialidade.

Ejemplo

Um servidor web retorna stack traces completos em páginas de erro, revelando caminhos absolutos do servidor e bibliotecas em uso; ou a aplicação exibe o token de sessão do usuário em logs do navegador acessíveis via JavaScript; ou uma API retorna mensagens de erro que confirmam quais usuários existem no sistema.

Cómo mitigar

Implemente tratamento genérico de erros (nunca exiba detalhes técnicos ao usuário final), revise logs e respostas da API para garantir que dados sensíveis não sejam registrados ou retornados, e use variáveis de ambiente para armazenar secrets em vez de hardcodá-los no código ou comentários.

CVE-2026-67071MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or TransferEPSS 0.2%CVE-2025-65000LOWExposure of SSH Private Keys in Remote Alert Handlers (Linux) RuleEPSS 0.2%CVE-2026-86740MEDIUMSnipe-IT before 8.7.0 Attachment Deletion Reports Success While File RemainsEPSS 0.2%CVE-2026-34214HIGHTrino: Iceberg REST catalog static and vended credentials are accessible via query JSONEPSS 0.2%CVE-2025-24884MEDIUMkube-audit-rest's example logging configuration could disclose secret values in the audit logEPSS 0.2%CVE-2026-1182MEDIUMImproper Removal of Sensitive Information Before Storage or Transfer in GitLabEPSS 0.2%CVE-2025-64326LOWWeblate leaks the IP of project members inviting users to assume reviewer roles in Audit logEPSS 0.2%CVE-2025-0011LOWImproper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address EPSS 0.2%CVE-2026-90860HIGHThe Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebVieEPSS 0.2%CVE-2026-32891CRITICALAnchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSEPSS 0.2%CVE-2025-20118MEDIUMCisco Application Policy Infrastructure Controller Authenticated Command Injection Due to Sensitive Disclosure VulnerabilityEPSS 0.2%CVE-2025-8860LOWQemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callbackEPSS 0.2%CVE-2025-65965HIGHGrype has a credential disclosure vulnerability in Grype JSON outputEPSS 0.1%CVE-2026-36178MEDIUMThe factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, poEPSS 0.1%CVE-2026-53604HIGHnebula-mesh: CA private key not zeroized on web mobile-bundle error pathsEPSS 0.1%CVE-2026-45046MEDIUMGryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive ContentEPSS 0.1%CVE-2024-5300MEDIUMAppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbdEPSS 0.1%CVE-2026-15811MEDIUMKronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changesEPSS 0.1%