Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2025-53742MEDIUMJenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, EPSS 0.2%CVE-2022-39351MEDIUMDependency-Track vulnerable to logging of API keys in clear text when handling API requests using keys with insufficient permissionsEPSS 0.2%CVE-2021-22509HIGHHandling of sensitive data in process memory in NetIQ Advance AuthenticationEPSS 0.2%CVE-2023-41095MEDIUMKeys Stored in Plaintext on Secure Vault High for Silabs OpenThread devicesEPSS 0.2%CVE-2024-9802MEDIUMConformance validation endpoint discloses detail about service to unauthenticated usersEPSS 0.2%CVE-2023-24439MEDIUMJenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file onEPSS 0.2%CVE-2023-24454MEDIUMJenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on tEPSS 0.2%CVE-2026-7163MEDIUMAssisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosureEPSS 0.2%CVE-2020-7516—A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allowEPSS 0.2%CVE-2025-14836MEDIUMZZCMS User Data Storage user_save.php cleartext storage in fileEPSS 0.2%CVE-2026-6332MEDIUMClear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVACEPSS 0.2%CVE-2025-5154MEDIUMPhonePe App SQLite Database databases cleartext storage in a file or on diskEPSS 0.2%CVE-2020-29502HIGHDell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A EPSS 0.2%CVE-2020-29500HIGHDell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locaEPSS 0.2%CVE-2026-67221MEDIUMRabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwordsEPSS 0.2%CVE-2024-4840MEDIUMRhosp-director: cleartext passwords exposed in logsEPSS 0.2%CVE-2022-45439MEDIUMA pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. EPSS 0.2%CVE-2026-55985MEDIUMTycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive InformationEPSS 0.2%CVE-2026-57287MEDIUMJenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying hiEPSS 0.2%CVE-2026-33003MEDIUMJenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they EPSS 0.2%