Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2026-18591LOWMeesho Online Shopping App com.meesho.supply cleartext storageEPSS 0.1%CVE-2026-16213MEDIUMFantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storageEPSS 0.1%CVE-2025-6748LOWBharti Airtel Thanks App files cleartext storage in a file or on diskEPSS 0.1%CVE-2023-41096MEDIUMKeys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet devicesEPSS 0.1%CVE-2026-45362LOWSangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.EPSS 0.1%CVE-2026-8804MEDIUMCleartext Storage of Sensitive Information for Puppet Resource APIEPSS 0.1%CVE-2025-59105HIGHUnencrypted Flash Storage in dormakaba access managerEPSS 0.1%CVE-2025-53103MEDIUMJUnit OpenTestReportGeneratingListener can leak Git credentialsEPSS 0.1%CVE-2026-4130HIGHStorage of Sensitive Information in Cleartext in NI SystemLinkEPSS 0.1%CVE-2026-59327MEDIUMCleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch ConfigurationsEPSS 0.1%CVE-2026-86443MEDIUMCleartext Storage of Sensitive Information VulnerabilityEPSS 0.1%CVE-2017-20040MEDIUMSICUNET Access Controller Password Storage cleartext storageEPSS 0.1%CVE-2024-40750MEDIUMLinksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during apEPSS 0.1%CVE-2026-22276MEDIUMDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive InformEPSS 0.1%CVE-2026-16802MEDIUMCleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local EPSS 0.1%CVE-2025-48428MEDIUMCleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to thEPSS 0.1%CVE-2026-34490MEDIUMXAAP Android Data Stored in Unencrypted DatabaseEPSS 0.1%CVE-2025-3784MEDIUMInformation Disclosure Vulnerability in GX Works2EPSS 0.1%CVE-2025-58401MEDIUMObsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthEPSS 0.1%CVE-2025-14815CRITICALInformation Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64EPSS 0.1%