Fallos del tipo CWE-524

72 resultados

Armazenamento de Informações Sensíveis em Cache

Ocorre quando dados sensíveis (senhas, tokens, chaves de API, dados pessoais) são armazenados em cache sem proteção adequada. Um atacante com acesso ao cache consegue recuperar essas informações comprometendo a segurança da aplicação.

Ejemplo

Um navegador ou aplicativo armazena em cache uma resposta HTTP contendo token de autenticação ou dados de cartão de crédito. Se o cache não for criptografado e o dispositivo for comprometido, o atacante extrai essas credenciais diretamente dos arquivos de cache.

Cómo mitigar

Marque respostas com dados sensíveis como não-cacheáveis (Cache-Control: no-store, no-cache), use criptografia para dados em cache e implemente limpeza automática de cache após logout ou timeout. Nunca armazene credenciais em cache localmente sem encriptação.

CVE-2026-59213LOWOpen WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)EPSS 0.3%CVE-2026-88059MEDIUMAngular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`EPSS 0.3%CVE-2025-14806MEDIUMIBM Planning Analytics Information DisclosureEPSS 0.3%CVE-2026-0281LOWPAN-OS: Information Disclosure Vulnerability in Management Web InterfaceEPSS 0.3%CVE-2025-61598MEDIUMDiscourse is missing Cache-Control response header on error responsesEPSS 0.3%CVE-2026-64792HIGHJoomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensionsEPSS 0.2%CVE-2026-84933MEDIUMundici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared cachesEPSS 0.2%CVE-2025-43410LOWThe issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.2EPSS 0.2%CVE-2024-33004MEDIUMInsecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)EPSS 0.2%CVE-2026-48901HIGHJoomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objectsEPSS 0.2%CVE-2026-59903MEDIUMNetty: Cache Poisoning and Information Disclosure via CORS Vary Header OverwriteEPSS 0.2%CVE-2026-65755HIGHJoomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensionEPSS 0.2%CVE-2025-69581MEDIUMAn issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even afteEPSS 0.2%CVE-2026-22741LOWStatic resource cache poisoning in Spring MVC and WebFluxEPSS 0.2%CVE-2022-32909MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in iOS 16. An app may be able to access user-sensitive data.EPSS 0.2%CVE-2026-32244MEDIUMDiscourse: Cached outdated summaries can leak removed contentEPSS 0.2%CVE-2024-41906MEDIUMA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not EPSS 0.2%CVE-2026-50169MEDIUMAngular Service Worker Policy-Bypass & Credential-Stripping VulnerabilitiesEPSS 0.2%CVE-2026-47225MEDIUMImproper Search Cache Isolation for Scoped Search API Keys in TypesenseEPSS 0.2%CVE-2026-25703HIGHPotential information leakage from manager /network/graph API in NeuVectorEPSS 0.2%