Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2025-30124CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password isEPSS 0.3%CVE-2024-29956MEDIUMcleartext password in supportsave logs when a user schedules a switch Supportsave from Brocade SANnavEPSS 0.3%CVE-2023-48707MEDIUMCleartext Storage of Sensitive Information in codeigniter4/shieldEPSS 0.3%CVE-2025-7426CRITICALMINOVA TTA Information Disclosure and Credential ExposureEPSS 0.3%CVE-2019-3937—Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuratEPSS 0.3%CVE-2026-31848HIGHReversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+EPSS 0.3%CVE-2026-25751CRITICALFUXA Unauthenticated Exposure of Plaintext Database CredentialsEPSS 0.3%CVE-2024-42451HIGHA vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by caEPSS 0.3%CVE-2025-12772HIGHPlaintext Switch admin login password is seen in Brocade SANnav support saveEPSS 0.3%CVE-2024-23584MEDIUMHCL BigFix Asset Discovery is affected by a security vulnerabilityEPSS 0.3%CVE-2025-23027MEDIUMBASEHUB_TOKEN commited in next-forgeEPSS 0.3%CVE-2025-53672MEDIUMJenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controllEPSS 0.3%CVE-2022-45787MEDIUMApache James MIME4J: Temporary File Information Disclosure in MIME4J TempFileStorageProviderEPSS 0.3%CVE-2025-0142MEDIUMZoom Jenkins Marketplace plugin - Cleartext Storage of Sensitive InformationEPSS 0.3%CVE-2025-2120LOWThinkware Car Dashcam F800 Pro Configuration File hostapd.conf cleartext storage in a file or on diskEPSS 0.3%CVE-2020-14480MEDIUMDue to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to cerEPSS 0.3%CVE-2025-62261MEDIUMLiferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92EPSS 0.3%CVE-2020-25678—A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching thEPSS 0.3%CVE-2024-46383LOWHathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintextEPSS 0.3%CVE-2026-55885MEDIUMGrav: Admin Backup Zip File Exposes Account Credentials and Configuration SecretsEPSS 0.3%