Fallos del tipo CWE-347

534 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2025-25292CRITICALRuby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)EPSS 63.8%CVE-2025-59718CRITICALA improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiEPSS 63.4%KEVCVE-2013-3900MEDIUMWinVerifyTrust Signature Validation VulnerabilityEPSS 44.6%KEVCVE-2018-0114A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens uEPSS 42.7%CVE-2020-1464HIGHWindows Spoofing VulnerabilityEPSS 41.1%KEVCVE-2024-9487CRITICALAn Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabledEPSS 25.1%CVE-2025-59719CRITICALAn improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 tEPSS 25.0%CVE-2025-25291CRITICALruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)EPSS 19.5%CVE-2024-45607MEDIUMwhatsapp-api-js fails to validate message's signatureEPSS 14.5%CVE-2026-48558CRITICALSimpleHelp Authentication Bypass via Missing OIDC JWT Signature VerificationEPSS 11.5%CVE-2026-40372CRITICALASP.NET Core Elevation of Privilege VulnerabilityEPSS 11.2%CVE-2024-45409CRITICALThe Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectorEPSS 10.7%CVE-2025-29775CRITICALxml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue CommentEPSS 9.4%CVE-2025-29774CRITICALxml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo ReferencesEPSS 9.0%CVE-2025-59934CRITICALFormbricks missing JWT signature verificationEPSS 8.0%CVE-2020-9047MEDIUMexacqVision Software - Improper Verification of Cryptographic SignatureEPSS 7.8%CVE-2026-29000CRITICALpac4j-jwt JwtAuthenticator Authentication BypassEPSS 5.9%CVE-2020-2021CRITICALPAN-OS: Authentication Bypass in SAML AuthenticationEPSS 4.4%KEVCVE-2025-47827MEDIUMIn IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. UltimaEPSS 4.0%KEVCVE-2026-10795HIGHUpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpcEPSS 3.6%