Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2017-3214—The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.EPSS 0.6%CVE-2015-8314HIGHThe Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persisEPSS 0.6%CVE-2021-23878HIGHClear text storage of sensitive Information in ENSEPSS 0.6%CVE-2023-24450MEDIUMJenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be EPSS 0.6%CVE-2019-6549—An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or SoftwareEPSS 0.6%CVE-2019-18238—In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive informatioEPSS 0.6%CVE-2023-4392LOWControl iD Gerencia Web Cookie cleartext storageEPSS 0.6%CVE-2023-27706HIGHBitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other loEPSS 0.6%CVE-2025-34270MEDIUMNagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not ObfuscatedEPSS 0.6%CVE-2020-15085MEDIUMClient caching login operation with plaintext password in Saleor StorefrontEPSS 0.6%CVE-2020-15784—A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuEPSS 0.6%CVE-2026-8596HIGHCleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve pathEPSS 0.6%CVE-2024-4235LOWNetgear DG834Gv5 Web Management Interface cleartext storageEPSS 0.6%CVE-2022-43757CRITICALRancher: Exposure of sensitive fieldsEPSS 0.6%CVE-2023-24586LOWCleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authentEPSS 0.5%CVE-2024-4540HIGHKeycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookieEPSS 0.5%CVE-2023-5384HIGHInfinispan: credentials returned from configuration as clear textEPSS 0.5%CVE-2021-20995MEDIUMWAGO: Managed Switches: Storage of user credentials in a cookieEPSS 0.5%CVE-2022-37785HIGHAn issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.EPSS 0.5%CVE-2025-34206CRITICALVasion Print (formerly PrinterLogic) Insecure Shared Storage PermissionsEPSS 0.5%