Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2025-2182MEDIUMPAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK)EPSS 0.1%CVE-2025-34427HIGHMailEnable < 10.54 Cleartext Credential Storage in AUTH.TABEPSS 0.1%CVE-2024-25023MEDIUMIBM QRadar Suite Software information disclosureEPSS 0.1%CVE-2023-46294LOWAn issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwEPSS 0.1%CVE-2024-29954MEDIUMpassword management API prints sensitive information in log filesEPSS 0.1%CVE-2024-28807MEDIUMAn issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop managementEPSS 0.1%CVE-2024-23942HIGHMB connect line: Configuration File on the client workstation is not encryptedEPSS 0.1%CVE-2024-8070HIGHCWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binaryEPSS 0.1%CVE-2024-29952MEDIUMClear text storage of sensistive information by manipulating command variables EPSS 0.1%CVE-2026-55997HIGHLong-lived Rancher registration token exposed in plaintextEPSS 0.1%CVE-2026-73834MEDIUMMust-gather: must-gather: embedded secret data in acm wrapper crs collected without redactionEPSS 0.1%CVE-2026-43942MEDIUMelecterm: Full process.env exposed to renderer via window.pre.env in electermEPSS 0.1%CVE-2024-51993LOWPassword is stored in clear in the database in Combodo iTopEPSS 0.1%CVE-2024-41688HIGHCleartext Storage of Sensitive Information VulnerabilityEPSS 0.1%CVE-2024-28024MEDIUMA vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessibEPSS 0.1%CVE-2024-58023HIGHInformation disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.EPSS 0.1%CVE-2025-59450MEDIUMThe YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.EPSS 0.1%CVE-2026-42408MEDIUMBIG-IP DNS tmsh vulnerabilityEPSS 0.1%CVE-2026-16213MEDIUMFantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storageEPSS 0.1%CVE-2026-28758MEDIUMBIG-IP iControl REST vulnerabilityEPSS 0.1%