Fallos del tipo CWE-359

197 resultados

Violação de Privacidade

Ocorre quando a aplicação expõe dados pessoais ou sensíveis sem consentimento do usuário, ou com controle de acesso inadequado. O risco é que informações privadas (credenciais, dados financeiros, localização, etc.) fiquem acessíveis a quem não deveria ter acesso.

Ejemplo

Uma API retorna token de sessão, ID de usuário ou dados de perfil em URLs, logs públicos, ou respostas de erro visíveis; ou um endpoint de listar usuários não valida permissões, permitindo qualquer cliente enumerar dados sensíveis de terceiros.

Cómo mitigar

Implemente controle de acesso granular em cada endpoint sensível; nunca exponha dados pessoais em URLs, logs ou respostas de erro; criptografe dados em trânsito e em repouso; aplique princípio do menor privilégio e audite acessos regularmente.

CVE-2023-50719HIGHXWiki Platform Solr search discloses password hashes of all usersEPSS 83.5%CVE-2022-0482CRITICALExposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentsEPSS 38.7%CVE-2023-36052HIGHAzure CLI REST Command Information Disclosure VulnerabilityEPSS 21.5%CVE-2021-22876MEDIUMcurl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credenEPSS 5.3%CVE-2024-45591MEDIUMXWiki Platform document history including authors of any page exposed to unauthorized actorsEPSS 3.4%CVE-2022-24819MEDIUMUnauthenticated user can retrieve the list of users through uorgsuggest.vmEPSS 3.3%CVE-2026-28950MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7EPSS 2.9%CVE-2022-0155HIGHExposure of Private Personal Information to an Unauthorized Actor in follow-redirects/follow-redirectsEPSS 2.4%CVE-2023-28303LOWWindows Snipping Tool Information Disclosure VulnerabilityEPSS 2.0%CVE-2024-11396MEDIUMEvent monster <= 1.4.3 - Information Exposure Via Visitors List ExportEPSS 2.0%CVE-2019-15623Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup ServerEPSS 1.9%CVE-2017-16769Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadatEPSS 1.9%CVE-2021-28559MEDIUMAdobe Acrobat Reader privacy violation vulnerability could lead to privilege escalationEPSS 1.6%CVE-2024-30056HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.6%CVE-2021-3980MEDIUMExposure of Private Personal Information to an Unauthorized Actor in elgg/elggEPSS 1.5%CVE-2023-36018HIGHVisual Studio Code Jupyter Extension Spoofing VulnerabilityEPSS 1.5%CVE-2024-26192HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.5%CVE-2025-54125HIGHXWiki Platform: Password and email exposure in xml.vm fieldsEPSS 1.3%CVE-2024-29987MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.2%CVE-2025-43227HIGHThis issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6EPSS 1.2%