Fallos del tipo CWE-347

640 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2020-8324MEDIUMA vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could EPSS 0.4%CVE-2024-26194HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-72889CRITICALNet::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verifyEPSS 0.3%CVE-2024-52958CRITICALiota C.ai Conversational Platform - Improper Verification of Cryptographic SignatureEPSS 0.3%CVE-2026-50722HIGHIKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payloadEPSS 0.3%CVE-2024-50347MEDIUMLaravel Reverb has Missing API Signature VerificationEPSS 0.3%CVE-2024-11696MEDIUMThe application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flawEPSS 0.3%CVE-2026-76581CRITICALWPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization ConfusionEPSS 0.3%CVE-2026-55735HIGHGuardian.revoke/3 acts on unverified token claims, allowing forged-token session revocationEPSS 0.3%CVE-2019-1812MEDIUMCisco NX-OS CLI Command Software Image Signature Verification VulnerabilitiesEPSS 0.3%CVE-2019-1813MEDIUMCisco NX-OS CLI Command Software Image Signature Verification VulnerabilityEPSS 0.3%CVE-2026-80098CRITICALCopilot Studio Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-22097CRITICALMissing firmware validation allows remote code executionEPSS 0.3%CVE-2024-38069HIGHWindows Enroll Engine Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-33026CRITICALnginx-ui Backup Restore Allows Tampering with Encrypted BackupsEPSS 0.3%CVE-2026-54155HIGHnode-opcua: Missing nonce verification in UserNameIdentityToken authenticationEPSS 0.3%CVE-2025-23206LOWIAM OIDC custom resource allows connection to unauthorized OIDC provider in aws-cdkEPSS 0.3%CVE-2024-49393MEDIUMMutt: neomutt: to and cc email header fields are not protected by cryptographic signingEPSS 0.3%CVE-2024-49394MEDIUMMutt: neomutt: in-reply-to email header field it not protected by cryptograpic signingEPSS 0.3%CVE-2026-10579CRITICALPicketlink-federation: auth bypass in picketlink saml unsolicited-responseEPSS 0.3%