Fallos del tipo CWE-347

640 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2026-74901CRITICALopenssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR FallbackEPSS 0.2%CVE-2026-2968MEDIUMCesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verificationEPSS 0.2%CVE-2017-12333A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a EPSS 0.2%CVE-2026-9832MEDIUMPayment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook EndpointEPSS 0.2%CVE-2026-49454CRITICALRelyra SAML SignatureValue not cryptographically verified -> authentication bypassEPSS 0.2%CVE-2026-58085HIGHMissing MAC validation in wg(4) packet decryptionEPSS 0.2%CVE-2023-54355HIGHPocketMine-MP 5.2.0 Server Crash via Incorrect EC CurveEPSS 0.2%CVE-2026-86304CRITICALMojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchorEPSS 0.2%CVE-2026-4600CRITICALVersions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameEPSS 0.2%CVE-2025-52550HIGHFirmware upgrade packages are unsignedEPSS 0.2%CVE-2026-76234HIGHlibcrux before 0.0.6 Cryptographic Implementation Bug FixesEPSS 0.2%CVE-2021-1453MEDIUMCisco IOS XE Software for the Catalyst 9000 Family Arbitrary Code Execution VulnerabilityEPSS 0.2%CVE-2020-10608In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI SyEPSS 0.2%CVE-2026-85394CRITICALpython-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC SecretEPSS 0.2%CVE-2026-42602HIGHazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replayEPSS 0.2%CVE-2026-65616HIGHPotential privilege escalation to JFrog administrator privilegesEPSS 0.2%CVE-2026-46423CRITICALRocket.Chat: SAML signature validation skipped when IdP certificate field is emptyEPSS 0.2%CVE-2025-41767HIGHSignature bypass on update uploadEPSS 0.2%CVE-2026-52767HIGHYesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`EPSS 0.2%CVE-2023-23940MEDIUMOpenZeppelin Contracts for Cairo is vulnerable to signature validation bypassEPSS 0.2%