Fallos del tipo CWE-347

639 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2024-42004HIGHA library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library canEPSS 0.8%CVE-2020-15240HIGHRegression in JWT Signature ValidationEPSS 0.8%CVE-2024-41145HIGHA library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. AEPSS 0.8%CVE-2026-3338HIGHPKCS7_verify Signature Validation Bypass in AWS-LCEPSS 0.8%CVE-2022-24771HIGHImproper Verification of Cryptographic Signature in node-forgeEPSS 0.8%CVE-2026-5588MEDIUMPKIX draft CompositeVerifier accepts empty signature sequence as valid.EPSS 0.8%CVE-2024-22461HIGHDell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentiaEPSS 0.8%CVE-2021-29455HIGHMissing validation of JWT signature in `grassrootza/grassroot-platform`EPSS 0.8%CVE-2025-2233HIGHSamsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass VulnerabilityEPSS 0.8%CVE-2024-42220HIGHA library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access pEPSS 0.7%CVE-2024-41165HIGHA library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privilegeEPSS 0.7%CVE-2024-43106HIGHA library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileEPSS 0.7%CVE-2017-15090An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signaturEPSS 0.7%CVE-2016-7064A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakageEPSS 0.7%CVE-2022-23610CRITICALImproper Verification of Cryptographic Signature in wire-serverEPSS 0.7%CVE-2026-12263HIGHAuthentication BypassEPSS 0.7%CVE-2026-9779HIGHATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution VulnerabilityEPSS 0.7%CVE-2021-3421A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seeminglyEPSS 0.7%CVE-2023-34058HIGHVMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges httpsEPSS 0.7%CVE-2023-28226MEDIUMWindows Enroll Engine Security Feature Bypass VulnerabilityEPSS 0.7%