Fallos del tipo CWE-359

213 resultados

Violação de Privacidade

Ocorre quando a aplicação expõe dados pessoais ou sensíveis sem consentimento do usuário, ou com controle de acesso inadequado. O risco é que informações privadas (credenciais, dados financeiros, localização, etc.) fiquem acessíveis a quem não deveria ter acesso.

Ejemplo

Uma API retorna token de sessão, ID de usuário ou dados de perfil em URLs, logs públicos, ou respostas de erro visíveis; ou um endpoint de listar usuários não valida permissões, permitindo qualquer cliente enumerar dados sensíveis de terceiros.

Cómo mitigar

Implemente controle de acesso granular em cada endpoint sensível; nunca exponha dados pessoais em URLs, logs ou respostas de erro; criptografe dados em trânsito e em repouso; aplique princípio do menor privilégio e audite acessos regularmente.

CVE-2022-41936MEDIUMExposure of Private Personal Information to an Unauthorized Actor in xwiki-platform-rest-serverEPSS 0.8%CVE-2023-22918MEDIUMA post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEEPSS 0.8%CVE-2026-20834MEDIUMWindows Spoofing VulnerabilityEPSS 0.8%CVE-2023-35151HIGHXWiki Platform may show email addresses in clear in REST resultsEPSS 0.7%CVE-2023-29203LOWUnauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm EPSS 0.7%CVE-2026-56171HIGHWindows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-66035HIGHAngular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLsEPSS 0.7%CVE-2024-27850MEDIUMThis issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, mEPSS 0.7%CVE-2023-7014MEDIUMAuthor Box, Guest Author and Co-Authors for Your Posts – Molongui <= 4.7.4 - Information Exposure via ma_debugEPSS 0.7%CVE-2026-56124HIGHphpUploader < 2.0.2 Unauthenticated Database Exposure via index modelEPSS 0.6%CVE-2019-25762HIGHJoomla! Component JoomProject 1.1.3.2 Information DisclosureEPSS 0.6%CVE-2026-24735HIGHApache Answer: Revision API Improper Access Control leads to Information DisclosureEPSS 0.6%CVE-2023-5983HIGHInformation Disclosure in Botanik Software Pharmacy AutomationEPSS 0.6%CVE-2026-62328HIGH9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage EndpointsEPSS 0.6%CVE-2024-7697HIGHLogical vulnerability in com.transsion.carlcareEPSS 0.6%CVE-2024-10267HIGHInformation Disclosure in transformeroptimus/superagiEPSS 0.6%CVE-2020-37173HIGHAVideo Platform 8.1 - Information Disclosure (User Enumeration)EPSS 0.6%CVE-2023-1936LOWExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.6%CVE-2025-5334HIGHExposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows EPSS 0.6%CVE-2023-2703HIGHInformation Disclosure in Finex Media's Competition Management SystemEPSS 0.6%