Fallos del tipo CWE-347

641 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2026-28198CRITICALPrivilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS ShellEPSS 0.2%CVE-2025-4371HIGHA potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical acceEPSS 0.2%CVE-2026-89086CRITICALIn the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proEPSS 0.2%CVE-2026-6328HIGHXQUIC Improper STREAM Frame Validation in Initial/Handshake PacketsEPSS 0.2%CVE-2026-85393HIGHnode-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm PaddingEPSS 0.2%CVE-2026-18092HIGHNet::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtreeEPSS 0.2%CVE-2026-57910CRITICALWatchGuard Agent improper authentication allows unauthenticated remote code executionEPSS 0.2%CVE-2024-7788HIGHSignatures in "repair mode" should not be trustedEPSS 0.2%CVE-2026-46349MEDIUMMastodon: LD-Signature Bypass via JSON-LD Named-Graph RestructuringEPSS 0.2%CVE-2026-68757HIGHPotential improper SAML signature verification in JFrog ArtifactoryEPSS 0.2%CVE-2025-20181MEDIUMA vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, locEPSS 0.2%CVE-2026-54783HIGHCoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messagesEPSS 0.2%CVE-2024-32911HIGHThere is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additioEPSS 0.2%CVE-2026-18152HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.2%CVE-2026-18568HIGHXML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic checkEPSS 0.2%CVE-2026-41669HIGHAdmidio: SAML Signature Validation Result Ignored — Forged AuthnRequests and LogoutRequests ProcessedEPSS 0.2%CVE-2026-6331LOWHMAC zero-length tag forgery in EVP_DigestVerifyFinalEPSS 0.2%CVE-2026-48815HIGHsigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforcedEPSS 0.2%CVE-2026-44497CRITICALZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale BufferEPSS 0.2%CVE-2022-20929HIGHA vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticatedEPSS 0.2%