Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2026-80058MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage EPSS 0.1%CVE-2025-54855MEDIUMAutomationDirect CLICK PLUS Cleartext Storage of Sensitive InformationEPSS 0.1%CVE-2024-9432MEDIUMCleartext Storage of Sensitive Information vulnerability has been discovered in OpenText™ Vertica.EPSS 0.1%CVE-2025-7215LOWFNKvision FNK-GU2 wpa_supplicant.conf cleartext storageEPSS 0.1%CVE-2025-41647MEDIUMLenze: Plaintext Password Disclosure in PLC Designer V4 InterfaceEPSS 0.1%CVE-2025-3395HIGHIncorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.ThEPSS 0.1%CVE-2025-40753MEDIUMA vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (EPSS 0.1%CVE-2025-40752MEDIUMA vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (EPSS 0.1%CVE-2025-7397MEDIUMCLI history displays inline passwordsEPSS 0.1%CVE-2025-11009MEDIUMInformation Disclosure Vulnerability in GT Designer3EPSS 0.1%CVE-2025-33081LOWMultiple Vulnerabilities in IBM Concert Software.EPSS 0.1%CVE-2024-39674MEDIUMPlaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.1%CVE-2025-53755MEDIUMCleartext Storage Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.1%CVE-2025-41458MEDIUMInsecure data storage vulnerability in Two App Studio Journey v5.5.9 for iOSEPSS 0.1%CVE-2025-63729CRITICALAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA CertifEPSS 0.1%CVE-2025-54342LOWA vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive IEPSS 0.1%CVE-2025-54464HIGHCleartext Storage Vulnerability in ZKTeco WL20EPSS 0.1%CVE-2026-24311MEDIUMInsecure Storage Protection vulnerability in SAP Customer Checkout 2.0EPSS 0.1%CVE-2026-50267MEDIUMSteeltoe: TLS private keys written to /tmp with default permissions, never deletedEPSS 0.1%CVE-2026-41520HIGHCillium exposes sensitive information included in the cilium-bugtool debug archiveEPSS 0.1%