Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2026-46622HIGHSolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breachEPSS 0.3%CVE-2026-55885MEDIUMGrav: Admin Backup Zip File Exposes Account Credentials and Configuration SecretsEPSS 0.3%CVE-2024-46383LOWHathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintextEPSS 0.3%CVE-2024-7259MEDIUMOvirt-engine: potential exposure of cleartext provider passwords via web uiEPSS 0.3%CVE-2025-10464MEDIUMCleartext password storage in Birtech Information Technologies' SensawayEPSS 0.3%CVE-2026-3221MEDIUMSensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker wEPSS 0.3%CVE-2025-54537MEDIUMIn JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshotsEPSS 0.3%CVE-2025-54538MEDIUMIn JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" commandEPSS 0.3%CVE-2021-33716—A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1EPSS 0.3%CVE-2025-46633HIGHCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt EPSS 0.3%CVE-2023-3950MEDIUMCleartext Storage of Sensitive Information in GitLabEPSS 0.3%CVE-2026-82699MEDIUMsambitraj Student Management System Password aca.sql cleartext storageEPSS 0.3%CVE-2026-65599MEDIUMn8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT HeaderEPSS 0.2%CVE-2024-45862HIGHCleartext Storage of Sensitive Information in Kastle Systems Access Control SystemEPSS 0.2%CVE-2023-48305MEDIUMNextcloud Server user_ldap app logs user passwords in the log file on level debugEPSS 0.2%CVE-2025-65320HIGHAbacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The applicatEPSS 0.2%CVE-2025-63208HIGHAn issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive EPSS 0.2%CVE-2023-41964MEDIUMBIG-IP and BIG-IQ Database Variable vulnerabilityEPSS 0.2%CVE-2026-45040MEDIUMRustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]EPSS 0.2%CVE-2026-34214HIGHTrino: Iceberg REST catalog static and vended credentials are accessible via query JSONEPSS 0.2%