Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2026-42151HIGHPrometheus Azure AD remote write OAuth client secret exposed via config APIEPSS 0.4%CVE-2022-20660MEDIUMCisco IP Phones Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-6874HIGHZigbee Unauthenticated DoS via NWK Sequence number manipulationEPSS 0.4%CVE-2024-36790HIGHNetgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.EPSS 0.3%CVE-2024-52525LOWNextcloud Server User password is available in memory of the PHP processEPSS 0.3%CVE-2025-34200HIGHVasion Print (formerly PrinterLogic) Network Account Password Stored in CleartextEPSS 0.3%CVE-2024-7783MEDIUMImproper Storage of Sensitive Information in Bearer Token in mintplex-labs/anything-llmEPSS 0.3%CVE-2024-46340CRITICALTL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plainteEPSS 0.3%CVE-2025-26495HIGHSensitive Data Exposure in Tableau ServerEPSS 0.3%CVE-2024-8459HIGHPLANET Technology switch devices - Cleartext storage of SNMPv3 users' passwordsEPSS 0.3%CVE-2023-27370MEDIUMNETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure VulnerabilityEPSS 0.3%CVE-2025-27623MEDIUMJenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via RESTEPSS 0.3%CVE-2023-25596MEDIUMAuthenticated Sensitive Information Disclosure in ClearPass Policy ManagerEPSS 0.3%CVE-2024-43429MEDIUMMoodle: user information visibility control issues in gradebook reportsEPSS 0.3%CVE-2025-23215CRITICALPMD Designer's release key passphrase (GPG) available on Maven Central in cleartextEPSS 0.3%CVE-2026-33026CRITICALnginx-ui Backup Restore Allows Tampering with Encrypted BackupsEPSS 0.3%CVE-2023-30530MEDIUMJenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on thEPSS 0.3%CVE-2023-30527MEDIUMJenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins contrEPSS 0.3%CVE-2022-21818MEDIUMNVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user on a network after siEPSS 0.3%CVE-2023-28345MEDIUMAn issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console pasEPSS 0.3%