Fallos del tipo CWE-347

639 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2021-29500HIGHMissing validation of JWT signatureEPSS 0.6%CVE-2023-28610CRITICALThe update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update imaEPSS 0.6%CVE-2021-3051HIGHCortex XSOAR: Authentication Bypass in SAML AuthenticationEPSS 0.6%CVE-2023-22742MEDIUMlibgit2 fails to verify SSH keys by defaultEPSS 0.6%CVE-2025-13662HIGHImproper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1EPSS 0.6%CVE-2019-10136MEDIUMIt was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired,EPSS 0.6%CVE-2023-39969CRITICALuthenticode signature validation bypass vulnerabilityEPSS 0.6%CVE-2026-10754HIGHPega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.EPSS 0.6%CVE-2023-5747HIGHCommand injection via wave install fileEPSS 0.6%CVE-2025-33074HIGHAzure Functions Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-15265CRITICALTenable Agent Path Traversal Leading to Remote Code ExecutionEPSS 0.6%CVE-2020-22653CRITICALIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.6%CVE-2024-48948MEDIUMThe Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at EPSS 0.6%CVE-2026-27962CRITICALAuthlib JWS JWK Header Injection: Signature Verification BypassEPSS 0.5%CVE-2025-54369CRITICALNode-SAML SAML Authentication BypassEPSS 0.5%CVE-2026-33895HIGHForge has signature forgery in Ed25519 due to missing S > L checkEPSS 0.5%CVE-2026-4115MEDIUMPuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verificationEPSS 0.5%CVE-2024-56161HIGHImproper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicEPSS 0.5%CVE-2022-39237MEDIUMDigital Signature Hash Algorithms Not Validated in sylabs/sifEPSS 0.5%CVE-2023-24025HIGHCRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signaEPSS 0.5%