Fallos del tipo CWE-310

89 resultados

Divulgação de informações sensíveis

Fraqueza genérica que descreve quando uma aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves criptográficas) a usuários não autorizados. O risco está em não proteger adequadamente informações críticas em trânsito, em repouso ou em logs/erros.

Ejemplo

Uma API retorna mensagens de erro detalhadas que revelam paths internos do servidor; um arquivo de configuração com credenciais é commitado no repositório público; dados sensíveis são logados em texto plano e ficam acessíveis em arquivos de log do servidor.

Cómo mitigar

Implemente criptografia para dados em trânsito (HTTPS/TLS) e em repouso; sanitize mensagens de erro para não expor detalhes técnicos; audite logs e variáveis de ambiente para remover credenciais; use gerenciadores de secrets (Vault, AWS Secrets Manager) em vez de hardcoding.

CVE-2021-41995HIGHPingID Mac Login prior to 1.1 vulnerable to pre-computed dictionary attacksEPSS 0.8%CVE-2025-48823MEDIUMWindows Cryptographic Services Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-5136MEDIUMTmall Demo Payment Identifier pay random valuesEPSS 0.6%CVE-2025-9146HIGHLinksys E5600 Firmware checkFw.sh verify_gemtek_header risky encryptionEPSS 0.5%CVE-2021-42001HIGHPingID Desktop encryption libraries misconfiguration can lead to sensitive data exposureEPSS 0.5%CVE-2021-41992HIGHPingID Windows Login RSA cryptographic weakness with possible offline MFA bypassEPSS 0.5%CVE-2025-0784MEDIUMIntelbras InControl Registered User usuario cleartext transmissionEPSS 0.5%CVE-2023-44303HIGH RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncrypEPSS 0.5%CVE-2017-13091The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including improperly specified padding in CBC mode allows use of an EDA tool as a decryption oracleEPSS 0.4%CVE-2017-13092The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including improperly specified HDL syntax allows use of an EDA tool as a decryption oracleEPSS 0.4%CVE-2017-13095The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including modification of a license-deny response to a license grantEPSS 0.4%CVE-2017-13096The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including modification of Rights Block to remove or relax access controlEPSS 0.4%CVE-2017-13097The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including modification of Rights Block to remove or relax license requirementEPSS 0.4%CVE-2017-13093The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including modification of encrypted IP cyphertext to insert hardware trojansEPSS 0.4%CVE-2022-23724MEDIUMPingID Integration for Windows Login MFA BypassEPSS 0.4%CVE-2025-10671MEDIUMyouth-is-as-pale-as-poetry e-learning JWT Token JwtUtils.java encryptSecret random valuesEPSS 0.4%CVE-2026-82555MEDIUMTOTOLINK N600R Authentication cstecgi.cgi loginAuth random valuesEPSS 0.4%CVE-2025-8205MEDIUMComodo Dragon IP DNS Leakage Detector cleartext transmissionEPSS 0.4%CVE-2024-26228HIGHWindows Cryptographic Services Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2020-8897MEDIUMRobustness weakness in AWS KMS and Encryption SDKsEPSS 0.4%