Fallos del tipo CWE-347

642 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2026-84185MEDIUMJwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verificationEPSS 0.1%CVE-2025-64456HIGHIn JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalationEPSS 0.1%CVE-2025-30064HIGHPossibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT keyEPSS 0.1%CVE-2026-2625MEDIUMRust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verificationEPSS 0.1%CVE-2025-54549MEDIUMCryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISOEPSS 0.1%CVE-2026-48791LOWSigstore Java has a vulnerability with bundle verification of integratedTimeEPSS 0.1%CVE-2026-4541LOWjanmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verificationEPSS 0.1%CVE-2026-14837HIGHSSH Enablement Signature Verification BypassEPSS 0.1%CVE-2024-36334HIGHImproper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory toEPSS 0.1%CVE-2025-46774MEDIUMAn Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version EPSS 0.1%CVE-2026-87732MEDIUMAn issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticateEPSS 0.1%CVE-2026-28199MEDIUMSensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS ShellEPSS 0.1%CVE-2026-75946HIGHOMEN Gaming Hub – Potential Escalation of Privilege & Information DisclosureEPSS 0.1%CVE-2026-52486MEDIUMAn issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument moduleEPSS 0.1%CVE-2025-23364MEDIUMA vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signingEPSS 0.1%CVE-2026-17872MEDIUMCryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a saEPSS 0.1%CVE-2023-20940HIGHIn the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to localEPSS 0.1%CVE-2026-0392HIGHeParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-updateEPSS 0.1%CVE-2026-16742MEDIUMsystemd-homed: local privilege escalation via missing home-record signature verification on the authenticate pathEPSS 0.1%CVE-2026-28590HIGHIn multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escEPSS 0.1%