Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2026-19391MEDIUMInsights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archivesEPSS 0.2%CVE-2023-31925MEDIUMStorage of clear text password in Brocade SANnavEPSS 0.2%CVE-2022-47512MEDIUMSensitive Data Disclosure VulnerabilityEPSS 0.2%CVE-2025-55443CRITICALTelpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stEPSS 0.2%CVE-2024-6921HIGHCleartext Username and Password in NAC Telecommunication's NACPremiumEPSS 0.2%CVE-2026-6598MEDIUMlangflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in fileEPSS 0.2%CVE-2025-65278HIGHAn issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive iEPSS 0.2%CVE-2018-19009—Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti EPSS 0.2%CVE-2025-44614HIGHTinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plEPSS 0.2%CVE-2025-49728MEDIUMMicrosoft PC Manager Security Feature Bypass VulnerabilityEPSS 0.2%CVE-2025-44649HIGHIn the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive modEPSS 0.2%CVE-2024-33470MEDIUMAn issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passbacEPSS 0.2%CVE-2019-14890HIGHA vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentiEPSS 0.2%CVE-2025-12680MEDIUMBrocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680)EPSS 0.2%CVE-2025-25613HIGHFS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 wEPSS 0.2%CVE-2026-6796MEDIUMSanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in fileEPSS 0.2%CVE-2024-9798MEDIUMHealth endpoint offers list of onboarded services to unauthenticated usersEPSS 0.2%CVE-2024-52284HIGHRancher Fleet Helm Values are stored inside BundleDeployment in plain textEPSS 0.2%CVE-2024-28065MEDIUMIn Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.EPSS 0.2%CVE-2023-31423MEDIUMPossible information exposure through log file vulnerabilityEPSS 0.2%