Fallos del tipo CWE-223

12 resultados

Omissão de Informação Relevante para Segurança

Ocorre quando mensagens de erro, logs ou saídas do sistema não incluem detalhes essenciais para detecção e resposta a incidentes de segurança. Sem essas informações, ataques passam despercebidos, investigações ficam incompletas e a auditoria fica comprometida.

Ejemplo

Um sistema registra apenas 'Falha de autenticação' sem incluir IP de origem, timestamp, nome de usuário tentado ou quantidade de tentativas. Um atacante fazendo força bruta fica invisível nos logs, pois não há informação suficiente para gerar alertas ou rastrear o ataque.

Cómo mitigar

Implemente logs estruturados e completos: sempre registre contexto (IP, usuário, timestamp, tipo de erro). Use níveis de severidade apropriados e revise o que de fato aparece em logs de auditoria versus logs operacionais. Teste se alertas disparam sobre atividades suspeitas e se investigadores conseguem reconstruir eventos com as informações registradas.

CVE-2023-28360MEDIUMAn omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file tEPSS 0.8%CVE-2024-52813MEDIUMmatrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identityEPSS 0.5%CVE-2026-91859MEDIUMMISP Access Log Entry Overwritten by Error Controller's Second beforeFilter PassEPSS 0.5%CVE-2022-44646LOWIn JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settingsEPSS 0.4%CVE-2023-31191CRITICALDenial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark InnovationsEPSS 0.4%CVE-2023-29156MEDIUMDenial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark InnovationsEPSS 0.3%CVE-2022-22563MEDIUMDell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vuEPSS 0.2%CVE-2025-52926LOWIn scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface.EPSS 0.2%CVE-2026-90955MEDIUMMISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model LoadEPSS 0.2%CVE-2026-31890MEDIUMInspektor Gadget: Tracing Denial of Service via Event FloodingEPSS 0.1%CVE-2026-49426LOWIncorrect audit records for ptrace(2) syscall requestsEPSS 0.1%CVE-2025-35987MEDIUMOmission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: KernEPSS 0.1%