Fallos del tipo CWE-347

642 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2024-1149HIGHImproper validation of update packagesEPSS 0.1%CVE-2026-59112MEDIUMSignature validation vulnerability affecting DigiDoc applicationsEPSS 0.1%CVE-2022-41669HIGHA CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with loEPSS 0.1%CVE-2026-49834MEDIUMsigstore-go: Multi-log threshold bypass via single compromised logEPSS 0.1%CVE-2023-23436HIGH Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2023-23432HIGH Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2023-23433MEDIUM Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2025-68972MEDIUMIn GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that placesEPSS 0.1%CVE-2025-43903MEDIUMNSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signatEPSS 0.1%CVE-2023-23435MEDIUM Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2024-11957CRITICALArbitrary Code Execution in WPS OfficeEPSS 0.1%CVE-2023-36811MEDIUMArchive spoofing vulnerability in borgbackupEPSS 0.1%CVE-2025-20143MEDIUMCisco IOS XR Software Secure Boot Bypass VulnerabilityEPSS 0.1%CVE-2026-89169MEDIUMlive-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.EPSS 0.1%CVE-2026-14296HIGHnRF54H20: MCUBoot can be tricked to executing unauthenticated codeEPSS 0.1%CVE-2026-92718HIGHNuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only CacheEPSS 0.1%CVE-2026-79970MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper VerificaEPSS 0.1%CVE-2026-52686LOWWildcard CNAME proof validation bypassEPSS 0.1%CVE-2024-1721MEDIUMImproper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue aEPSS 0.1%CVE-2026-56865HIGHFix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlogEPSS 0.1%