Fallos del tipo CWE-347

640 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2026-33894HIGHForge has signature forgery in RSA-PKCS due to ASN.1 extra fieldEPSS 0.5%CVE-2023-34435HIGHA firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted networEPSS 0.5%CVE-2024-34358MEDIUMTYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageControllerEPSS 0.5%CVE-2016-20021CRITICALIn Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file bEPSS 0.5%CVE-2026-56207CRITICALApache Impala: SAML authentication bypass via forged bearer tokenEPSS 0.5%CVE-2025-47949CRITICALsamlify SAML Signature Wrapping attackEPSS 0.5%CVE-2020-12046Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an atEPSS 0.5%CVE-2025-68113MEDIUMALTCHA Proof-of-Work Vulnerable to Challenge Splicing and ReplayEPSS 0.5%CVE-2023-23772HIGHMotorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature vEPSS 0.5%CVE-2023-23773HIGHMotorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation foEPSS 0.5%CVE-2026-1529HIGHOrg.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validationEPSS 0.5%CVE-2023-23928MEDIUMreason-jose ignores signature checksEPSS 0.5%CVE-2024-8531HIGHCWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when anEPSS 0.5%CVE-2023-28228MEDIUMWindows Spoofing VulnerabilityEPSS 0.5%CVE-2026-62918HIGHMicrosoft Teams Spoofing VulnerabilityEPSS 0.5%CVE-2025-64787LOWAcrobat Reader | Improper Verification of Cryptographic Signature (CWE-347)EPSS 0.4%CVE-2026-59243CRITICALApache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)EPSS 0.4%CVE-2023-3347MEDIUMSamba: smb2 packet signing is not enforced when "server signing = required" is setEPSS 0.4%CVE-2025-64786LOWAcrobat Reader | Improper Verification of Cryptographic Signature (CWE-347)EPSS 0.4%CVE-2025-59334CRITICALLinkr allows manifest tampering leading to arbitrary file injectionEPSS 0.4%