Fallos del tipo CWE-347

640 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2023-24025HIGHCRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signaEPSS 0.5%CVE-2021-20319An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the iEPSS 0.5%CVE-2023-42806MEDIUMSnapshot signature not including HeadID will allow replay attacksEPSS 0.5%CVE-2023-1204MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 befoEPSS 0.5%CVE-2020-12042Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. AEPSS 0.5%CVE-2023-46234MEDIUMbrowserify-sign vulnerable via an upper bound check issue in `dsaVerify` that leads to a signature forgery attackEPSS 0.5%CVE-2024-13172HIGHImproper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows EPSS 0.5%CVE-2022-24759HIGHFailure to validate signature during handshake in @chainsafe/libp2p-noiseEPSS 0.5%CVE-2026-56451CRITICALA vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm speciEPSS 0.5%CVE-2024-48949CRITICALThe verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) ||EPSS 0.5%CVE-2023-50714MEDIUMThe Oauth2 PKCE implementation is vulnerableEPSS 0.5%CVE-2026-50010HIGHNetty's wrapping plain trust manager silently disables hostname verificationEPSS 0.5%CVE-2023-40178MEDIUM@node-saml/node-saml's validatePostRequestAsync does not include checkTimestampsValidityErrorEPSS 0.5%CVE-2020-10759A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, aEPSS 0.5%CVE-2018-25099CRITICALIn the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.EPSS 0.5%CVE-2023-20266MEDIUMA vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager SessioEPSS 0.5%CVE-2026-23687HIGHXML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP PlatformEPSS 0.5%CVE-2025-55229MEDIUMWindows Certificate Spoofing VulnerabilityEPSS 0.5%CVE-2026-33117CRITICALAzure SDK for Java Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2020-25166HIGHB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 0.5%