Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2022-41248MEDIUMJenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potenEPSS 0.4%CVE-2022-45897MEDIUMOn Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored clearteEPSS 0.4%CVE-2019-16638HIGHAn issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with siEPSS 0.4%CVE-2023-51702MEDIUMApache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer serviceEPSS 0.4%CVE-2022-42955HIGHThe PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.EPSS 0.4%CVE-2022-42956HIGHThe PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.EPSS 0.4%CVE-2023-27098HIGHTP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.EPSS 0.4%CVE-2026-83551HIGHCleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline pathEPSS 0.4%CVE-2023-32983MEDIUMJenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form, increasing the poteEPSS 0.4%CVE-2025-59102MEDIUMSecrets Stored in Plaintext in Database in dormakaba access managerEPSS 0.4%CVE-2025-27685HIGHVasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & PriEPSS 0.4%CVE-2023-32982MEDIUMJenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller wEPSS 0.4%CVE-2023-49341HIGHAn issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive EPSS 0.4%CVE-2024-55196HIGHInsufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords foEPSS 0.4%CVE-2024-31840MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated EPSS 0.4%CVE-2023-41335LOWTemporary storage of plaintext passwords during password changes in matrix synapseEPSS 0.4%CVE-2024-13843MEDIUMCleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a EPSS 0.4%CVE-2023-3489HIGHfirmwaredownload command could log servers passwords in clear textEPSS 0.4%CVE-2025-55334MEDIUMWindows Kernel Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2024-47529MEDIUMOpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)EPSS 0.4%