Fallos del tipo CWE-347

639 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2022-39299HIGHSignature bypass via multiple root elements in Passport-SAMLEPSS 3.4%CVE-2020-24429HIGHAcrobat Reader DC for macOS Signature Verification Bypass Could Lead to Privilege EscalationEPSS 3.0%CVE-2025-31489HIGHMinIO performs incomplete signature validation for unsigned-trailer uploadsEPSS 2.4%CVE-2024-8698HIGHKeycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloakEPSS 2.0%CVE-2018-16151HIGHIn verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation baEPSS 1.9%CVE-2018-16152HIGHIn verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation baEPSS 1.9%CVE-2025-23369HIGHImproper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper ValidationEPSS 1.6%CVE-2019-14859HIGHA flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. WithoutEPSS 1.5%CVE-2024-6800CRITICALAn XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identityEPSS 1.5%CVE-2026-47212MEDIUMSymfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event InjectionEPSS 1.5%CVE-2026-15013CRITICALSAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm ConfusionEPSS 1.5%CVE-2021-41831Timestamp Manipulation with Signature WrappingEPSS 1.5%CVE-2024-0567HIGHGnutls: rejects certificate chain with distributed trustEPSS 1.4%CVE-2020-15705MEDIUMGRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shimEPSS 1.4%CVE-2021-41830Double Certificate AttackEPSS 1.4%CVE-2020-15093HIGHImproper verification of signature threshold in toughEPSS 1.4%CVE-2021-41832Content Manipulation with Certificate Validation AttackEPSS 1.3%CVE-2023-5347CRITICALUnauthenticated Firmware UpgradeEPSS 1.3%CVE-2022-26510CRITICALA firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafteEPSS 1.3%CVE-2021-21239MEDIUMOpen default xmlsec1 key-type preferenceEPSS 1.3%