Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2018-16498—In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These EPSS 0.2%CVE-2026-73748LOWAuthenticated Sensitive Information Disclosure in HPE Networking Fabric ComposerEPSS 0.2%CVE-2024-45718MEDIUMSensitive data disclosure vulnerabilityEPSS 0.2%CVE-2024-53651MEDIUMA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CEPSS 0.2%CVE-2025-2181MEDIUMCheckov by Prisma Cloud: Cleartext Exposure of CredentialsEPSS 0.2%CVE-2026-33867CRITICALAVideo has Plaintext Video Password StorageEPSS 0.2%CVE-2025-56566MEDIUMMikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attackerEPSS 0.2%CVE-2025-67638MEDIUMJenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasEPSS 0.2%CVE-2024-54127MEDIUMExposure of Wi-Fi Credentials in Plaintext in TP-Link Archer C50EPSS 0.2%CVE-2024-56428MEDIUMThe local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for thEPSS 0.2%CVE-2020-10053—A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data,EPSS 0.2%CVE-2024-9991HIGHCleartext Storage of Sensitive Information Vulnerability in Philips Lighting DevicesEPSS 0.2%CVE-2025-50777HIGHThe firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerabEPSS 0.2%CVE-2025-0418MEDIUMValmet DNA user passwords in plain textEPSS 0.2%CVE-2025-12679HIGHPlain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0EPSS 0.2%CVE-2024-12094MEDIUMInformation Disclosure Vulnerability in TinxyEPSS 0.2%CVE-2024-56362HIGHNavidrome Stores JWT Secret in Plaintext in navidrome.dbEPSS 0.2%CVE-2026-38571MEDIUMCleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticatEPSS 0.2%CVE-2024-41690HIGHDefault Credential Storage in Plaintext VulnerabilityEPSS 0.2%CVE-2026-93763HIGHSilent plaintext persistence via unresolved callable database name in encryption schema mapEPSS 0.2%