Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2023-29471MEDIUMLightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clearEPSS 0.2%CVE-2026-93763HIGHSilent plaintext persistence via unresolved callable database name in encryption schema mapEPSS 0.2%CVE-2024-12079MEDIUMECOVACS lawnmowers cleartext storage of anti-theft PINEPSS 0.2%CVE-2026-93764HIGHPlaintext storage of encrypted fields via skipped embedded models in encryption schema generationEPSS 0.1%CVE-2022-2513HIGHCleartext Credentials Vulnerability on Hitachi Energy’s Multiple IED Connectivity Packages (IED ConnPacks) and PCM600 ProductsEPSS 0.1%CVE-2024-55928MEDIUMClear text secrets returned & Remote system secrets in clear textEPSS 0.1%CVE-2025-47820LOWFlock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.EPSS 0.1%CVE-2026-10786MEDIUMImproper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain clEPSS 0.1%CVE-2025-6224MEDIUMKey leakage in juju/utils certificatesEPSS 0.1%CVE-2025-4053MEDIUMUnauthorized creation of master key in Mifare Classic Be-Tech cardsEPSS 0.1%CVE-2025-2189MEDIUMInformation Disclosure Vulnerability in Tinxy Smart DevicesEPSS 0.1%CVE-2025-47824LOWFlock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.EPSS 0.1%CVE-2024-28327HIGHAsus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify routerEPSS 0.1%CVE-2024-50570MEDIUMA Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 tEPSS 0.1%CVE-2024-40594LOWThe OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible tEPSS 0.1%CVE-2024-53979HIGHAnsible collection "ibm.ibm_zhmc" has passwords in clear text in log file and in output of some modules when specified as inputEPSS 0.1%CVE-2025-53670MEDIUMJenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml fiEPSS 0.1%CVE-2024-36119LOWPassword confirmation stored in plain text via registration form in statamic/cmsEPSS 0.1%CVE-2022-2569MEDIUMARC Informatique PcVueEPSS 0.1%CVE-2023-26593HIGHCENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who canEPSS 0.1%