Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2025-53758MEDIUMDefault Credential Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.1%CVE-2024-25661HIGHIn Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop applicatEPSS 0.1%CVE-2022-42284MEDIUMNVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.EPSS 0.1%CVE-2025-48463LOWUnencrypted HTTP CommunicationEPSS 0.1%CVE-2023-32446MEDIUM Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious uEPSS 0.1%CVE-2023-32447MEDIUM Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local acEPSS 0.1%CVE-2026-75847MEDIUMSensitive attribute values stored in a non-sensitive public changes map in AshPaperTrailEPSS 0.1%CVE-2025-27460HIGHCVE-2025-27460EPSS 0.1%CVE-2026-77970MEDIUMSensitive fields nested in embedded values are not redacted in AshPaperTrail versionsEPSS 0.1%CVE-2023-32455MEDIUM Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious uEPSS 0.1%CVE-2025-34428HIGHMailEnable < 10.54 Cleartext Credential Storage in AUTH.SAVEPSS 0.1%CVE-2026-76385MEDIUMInformation Disclosure through Action Parameters in Venafi app for Splunk SOAREPSS 0.1%CVE-2026-66016MEDIUMRendered Artifactory Helm manifests may contain generated TLS private keysEPSS 0.1%CVE-2024-31415MEDIUMThe Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network manageEPSS 0.1%CVE-2023-32448MEDIUM PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the instEPSS 0.1%CVE-2025-0123MEDIUMPAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet CapturesEPSS 0.1%CVE-2022-4312MEDIUM A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized uEPSS 0.1%CVE-2024-47056MEDIUMMautic does not shield .env files from web trafficEPSS 0.1%CVE-2026-77250MEDIUMMCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissionsEPSS 0.1%CVE-2025-2182MEDIUMPAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK)EPSS 0.1%