Fallos del tipo CWE-347

639 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2022-39300HIGHSignature bypass via multiple root elements in node-SAMLEPSS 0.7%CVE-2021-32685CRITICALImproper Verification of Cryptographic Signature in tenvoyEPSS 0.7%CVE-2021-3406A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust EPSS 0.7%CVE-2021-22708A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to EPSS 0.7%CVE-2022-35929HIGHFalse positive signature verification in cosignEPSS 0.7%CVE-2022-46176MEDIUMCargo did not verify SSH host keysEPSS 0.6%CVE-2025-47934HIGHOpenPGP.js's message signature verification can be spoofedEPSS 0.6%CVE-2022-35930HIGHAbility to bypass attestation verification in sigstore PolicyControllerEPSS 0.6%CVE-2022-23655MEDIUMMissing server signature validation in OctoberCMSEPSS 0.6%CVE-2021-32977HIGHAVEVA System Platform Improper Verification of Cryptographic SignatureEPSS 0.6%CVE-2018-10470Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag andEPSS 0.6%CVE-2020-24439LOWAcrobat Reader DC for macOS Signature Validation BypassEPSS 0.6%CVE-2024-47943CRITICALImproper signature verification of firmware upgrade filesEPSS 0.6%CVE-2024-21669CRITICALHyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VCEPSS 0.6%CVE-2022-41340HIGHThe secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.EPSS 0.6%CVE-2024-42461MEDIUMIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.EPSS 0.6%CVE-2024-13990CRITICALMicroWorld eScan AV Insecure Update Mechanism Allows Man-in-the-Middle Replacement of UpdatesEPSS 0.6%CVE-2026-57098HIGHMicrosoft Remote Desktop App for Windows Information Disclosure VulnerabilityEPSS 0.6%CVE-2020-3308MEDIUMCisco Firepower Threat Defense Software Signature Verification Bypass VulnerabilityEPSS 0.6%CVE-2025-9485CRITICALOAuth Single Sign On – SSO (OAuth Client) <= 6.26.12 - Authentication Bypass via get_resource_owner_from_id_token()EPSS 0.6%