Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2023-26593HIGHCENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who canEPSS 0.1%CVE-2024-53865HIGHPython package "zhmcclient" has passwords in clear text in its HMC and API logsEPSS 0.1%CVE-2026-4387LOWUnencrypted storage of authentication state in StrongDM Desktop Application state.kv fileEPSS 0.1%CVE-2026-9274MEDIUMInformation Exposure Vulnerability in CP-Plus Wi-Fi CameraEPSS 0.1%CVE-2022-31697MEDIUMThe vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with aEPSS 0.1%CVE-2025-3442MEDIUMInformation Disclosure Vulnerability in TP-Link Tapo IoT Smart HubEPSS 0.1%CVE-2025-2922LOWNetis WF-2404 BusyBox Shell cleartext storageEPSS 0.1%CVE-2025-55280MEDIUMInformation Disclosure Vulnerability in ZKTeco WL20EPSS 0.1%CVE-2023-24964MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.1%CVE-2024-10523MEDIUMInformation Disclosure Vulnerability in TP-Link IoT Smart HubEPSS 0.1%CVE-2026-36176HIGHGNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows EPSS 0.1%CVE-2025-23291LOWNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized actioEPSS 0.1%CVE-2024-55582MEDIUMOxide before 6 has unencrypted Control Plane datastores.EPSS 0.1%CVE-2023-32483MEDIUM Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerability. An authenticated malicious user havinEPSS 0.1%CVE-2020-10706MEDIUMA flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This fEPSS 0.1%CVE-2025-32353HIGHKaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuraEPSS 0.1%CVE-2022-48310MEDIUMAn information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versionEPSS 0.1%CVE-2021-35526MEDIUMStorage of Sensitive Information Vulnerability in Hitachi ABB Power Grids System Data Manager – SDM600 ProductEPSS 0.1%CVE-2022-34910MEDIUMAn issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. HoweEPSS 0.1%CVE-2023-39210MEDIUMCleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an informaEPSS 0.1%