Fallos del tipo CWE-297

76 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (credenciais, chaves, PII, tokens) sejam expostos a entidades não autorizadas através de mensagens de erro, logs, respostas HTTP, variáveis de ambiente ou outros mecanismos. O risco está em revelar informações que facilitam ataques subsequentes ou violam privacidade.

Ejemplo

Uma aplicação web retorna stacktrace completo em erro 500, expondo caminhos do servidor, nomes de banco de dados e bibliotecas internas. Ou um endpoint retorna tokens de sessão no histórico de navegação visível. Ou logs com senhas em plain text ficar acessível ao grupo errado.

Cómo mitigar

Nunca exiba detalhes técnicos em respostas de erro (use mensagens genéricas ao cliente); revise logs para remover dados sensíveis; implemente Data Loss Prevention (DLP) nas camadas de saída; valide quem acessa logs, variáveis de ambiente e backups; use criptografia para credenciais em repouso.

CVE-2026-48144CRITICALApache Thrift: c_glib TLS Client Missing Hostname VerificationEPSS 0.3%CVE-2025-68637CRITICALApache Uniffle: Insecure SSL Configuration in Uniffle HTTP ClientEPSS 0.2%CVE-2023-34143MEDIUMImproper Validation of Certificate Vulnerability in Hitachi Device ManagerEPSS 0.2%CVE-2025-49015MEDIUMThe Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK wEPSS 0.2%CVE-2023-24568MEDIUM Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replaEPSS 0.2%CVE-2022-27890MEDIUMIt was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactoryEPSS 0.2%CVE-2024-2462MEDIUMAllow attackers to intercept or falsify data exchanges between the client and the serverEPSS 0.2%CVE-2026-66053MEDIUMApache Thrift: Python TSSLSocket Hostname Matcher ImportEPSS 0.2%CVE-2026-59638CRITICALJSSE hostname verifier CN-fallback enabled by default despite documented opt-inEPSS 0.2%CVE-2022-48307MEDIUMIt was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactorEPSS 0.2%CVE-2026-84197CRITICALIn Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and oEPSS 0.2%CVE-2025-42921MEDIUMIn JetBrains Toolbox App before 2.6 host key verification was missing in SSH pluginEPSS 0.2%CVE-2026-53583MEDIUMlibgit2: Inverted IP SubjectAltName Comparison in OpenSSL BackendEPSS 0.2%CVE-2022-48308MEDIUMIt was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactoryEPSS 0.2%CVE-2026-26214CRITICALXiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITMEPSS 0.2%CVE-2026-35563HIGHApache Directory LDAP API: LDAP client implementation does not verify if the server certificate matches the intended LDAP hostnameEPSS 0.2%CVE-2026-44393HIGHAn issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname vEPSS 0.2%CVE-2026-15243HIGHImproper Validation of Certificate in CAS ClientEPSS 0.2%CVE-2024-54019MEDIUMA improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 EPSS 0.2%CVE-2026-59272MEDIUMLog4j2 AmqpAppender disables TLS hostname verification by defaultEPSS 0.2%