Fallos del tipo CWE-359

213 resultados

Violação de Privacidade

Ocorre quando a aplicação expõe dados pessoais ou sensíveis sem consentimento do usuário, ou com controle de acesso inadequado. O risco é que informações privadas (credenciais, dados financeiros, localização, etc.) fiquem acessíveis a quem não deveria ter acesso.

Ejemplo

Uma API retorna token de sessão, ID de usuário ou dados de perfil em URLs, logs públicos, ou respostas de erro visíveis; ou um endpoint de listar usuários não valida permissões, permitindo qualquer cliente enumerar dados sensíveis de terceiros.

Cómo mitigar

Implemente controle de acesso granular em cada endpoint sensível; nunca exponha dados pessoais em URLs, logs ou respostas de erro; criptografe dados em trânsito e em repouso; aplique princípio do menor privilégio e audite acessos regularmente.

CVE-2024-4767MEDIUMIf the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. ThisEPSS 0.5%CVE-2025-43496HIGHThe issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS SeqEPSS 0.5%CVE-2025-43500HIGHA privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1,EPSS 0.5%CVE-2025-53765MEDIUMAzure Stack Hub Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-13008HIGHSession Token Disclosure in M-Files WebEPSS 0.5%CVE-2026-0102LOWMicrosoft Edge (Chromium-based) Defense in Depth VulnerabilityEPSS 0.5%CVE-2024-33271HIGHAn issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component.EPSS 0.5%CVE-2024-53258HIGHdownload_all_submissions allows student to download another student's submissions in AutolabEPSS 0.5%CVE-2024-11712MEDIUMWP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume DownloadEPSS 0.5%CVE-2023-34085LOWUser Attribute Disclosure via DynamoDB Data StoresEPSS 0.5%CVE-2026-73008MEDIUMWindows Biometric Service Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-34226HIGHHappy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookiesEPSS 0.5%CVE-2026-69351MEDIUMWindows Universal Plug and Play (UPnP) Device Host Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-62644MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal informatioEPSS 0.5%CVE-2024-38103MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-28387HIGHAn issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.EPSS 0.4%CVE-2025-53625HIGHDynamicPageList3 exposes hidden/suppressed usernamesEPSS 0.4%CVE-2024-45787HIGHInformation Disclosure VulnerabilityEPSS 0.4%CVE-2024-47085HIGHParameter Manipulation VulnerabilityEPSS 0.4%CVE-2024-47087HIGHInformation Disclosure VulnerabilityEPSS 0.4%