Fallos del tipo CWE-297

76 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (credenciais, chaves, PII, tokens) sejam expostos a entidades não autorizadas através de mensagens de erro, logs, respostas HTTP, variáveis de ambiente ou outros mecanismos. O risco está em revelar informações que facilitam ataques subsequentes ou violam privacidade.

Ejemplo

Uma aplicação web retorna stacktrace completo em erro 500, expondo caminhos do servidor, nomes de banco de dados e bibliotecas internas. Ou um endpoint retorna tokens de sessão no histórico de navegação visível. Ou logs com senhas em plain text ficar acessível ao grupo errado.

Cómo mitigar

Nunca exiba detalhes técnicos em respostas de erro (use mensagens genéricas ao cliente); revise logs para remover dados sensíveis; implemente Data Loss Prevention (DLP) nas camadas de saída; valide quem acessa logs, variáveis de ambiente e backups; use criptografia para credenciais em repouso.

CVE-2024-7346HIGHClient connections using default TLS certificates from OpenEdge may bypass TLS host name validationEPSS 0.2%CVE-2026-84393HIGHA improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.EPSS 0.2%CVE-2026-62243HIGHNetty 4.2.0 through 4.2.16 TLS Hostname Verification BypassEPSS 0.2%CVE-2026-84975HIGHPJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and GnuTLS backends)EPSS 0.2%CVE-2024-12925HIGHHost Header Injection in Akinsoft's QR MenuEPSS 0.2%CVE-2026-49457CRITICALQUIC has Broken TLS verificationEPSS 0.1%CVE-2026-12162MEDIUMImproper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclosEPSS 0.1%CVE-2026-44467HIGHClaude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote SessionsEPSS 0.1%CVE-2026-79636HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper ValidatiEPSS 0.1%CVE-2025-25253MEDIUMAn Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and beEPSS 0.1%CVE-2026-9744MEDIUMVulnerabilities exists in IBM Netezza SoftwareEPSS 0.1%CVE-2025-4295MEDIUMHost Header Injection in HotelRunner's B2BEPSS 0.1%CVE-2026-12730LOWImproper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containersEPSS 0.1%CVE-2026-79943MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper ValidatiEPSS 0.1%CVE-2026-91166MEDIUMWarpgate: Web SSH stores a jump host's key against the target's address, so it validates as the targetEPSS CVE-2026-63374CRITICALAnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofingEPSS