Fallos del tipo CWE-359

213 resultados

Violação de Privacidade

Ocorre quando a aplicação expõe dados pessoais ou sensíveis sem consentimento do usuário, ou com controle de acesso inadequado. O risco é que informações privadas (credenciais, dados financeiros, localização, etc.) fiquem acessíveis a quem não deveria ter acesso.

Ejemplo

Uma API retorna token de sessão, ID de usuário ou dados de perfil em URLs, logs públicos, ou respostas de erro visíveis; ou um endpoint de listar usuários não valida permissões, permitindo qualquer cliente enumerar dados sensíveis de terceiros.

Cómo mitigar

Implemente controle de acesso granular em cada endpoint sensível; nunca exponha dados pessoais em URLs, logs ou respostas de erro; criptografe dados em trânsito e em repouso; aplique princípio do menor privilégio e audite acessos regularmente.

CVE-2023-44255LOWAn exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 anEPSS 0.6%CVE-2025-43405HIGHA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, maEPSS 0.6%CVE-2025-43399HIGHThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS SequoiEPSS 0.6%CVE-2024-46979MEDIUMData leak of notification filters of users in XWiki PlatformEPSS 0.5%CVE-2026-58296HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-58297HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-29888MEDIUMSaleor vulnerable to customers addresses leak when using Warehouse as a `Pickup: Local stock only` delivery methodEPSS 0.5%CVE-2025-66171MEDIUMApache CloudStack: Any user can create a new VM from backups they should not have access toEPSS 0.5%CVE-2023-50053HIGHAn issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication procEPSS 0.5%CVE-2021-36723MEDIUMEmuse - eServices / eNvoice Exposure Of Private Personal InformationEPSS 0.5%CVE-2022-46168LOWGroup SMTP user emails are exposed in CC email headerEPSS 0.5%CVE-2024-13215MEDIUMElementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal PopupEPSS 0.5%CVE-2023-6695MEDIUMBeaver Themer <= 1.4.9 - Authenticated (Contributor+) Sensitive Information Exposure via shortcodeEPSS 0.5%CVE-2024-29986MEDIUMMicrosoft Edge for Android (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-30321HIGHA vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versioEPSS 0.5%CVE-2025-66172HIGHApache CloudStack: Any user can attach a volume in their VMs from backups they should not have access toEPSS 0.5%CVE-2023-2239HIGHExposure of Private Personal Information to an Unauthorized Actor in microweber/microweberEPSS 0.5%CVE-2022-2720MEDIUMIn affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value maskinEPSS 0.5%CVE-2023-25819MEDIUMDiscourse tags with no visibility are leaking into og:article:tagEPSS 0.5%CVE-2024-49025MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%