Fallos del tipo CWE-538

93 resultados

Exposição de informações sensíveis em arquivos ou diretórios acessíveis externamente

O aplicativo escreve dados sensíveis (senhas, tokens, chaves, dados pessoais) em arquivos ou diretórios que podem ser acessados por usuários não autorizados — seja via web, sistema de arquivos aberto, ou backup público. O risco é que um atacante leia esses arquivos e obtenha credenciais, dados privados ou material para escalar privilégios.

Ejemplo

Um sistema de e-commerce salva recibos com CPF, email e número de cartão (mascarado ou não) em um diretório /tmp/receipts acessível via HTTP; ou um desenvolvedor commita arquivo .env com credenciais de banco de dados no repositório público do GitHub.

Cómo mitigar

Nunca escreva dados sensíveis em arquivos compartilhados, públicos ou versionáveis; use variáveis de ambiente, cofres de secrets (como HashiCorp Vault), ou gestores de credenciais. Se necessário armazenar localmente, restrinja permissões de arquivo (chmod 600), criptografe o conteúdo e não exponha o diretório em URLs acessíveis.

CVE-2023-7062HIGHAdvanced File Manager Shortcodes <= 2.4 - Authenticated (Contributor+) Directory TraversalEPSS 0.7%CVE-2019-15793MEDIUMMishandling of file-system uid/gid with namespaces in shiftfsEPSS 0.7%CVE-2023-4480MEDIUMArbitrary File Read in Fusion File ManagerEPSS 0.7%CVE-2024-22433HIGH Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info inEPSS 0.6%CVE-2021-4471HIGHTG8 Firewall Unauthenticated User Password DisclosureEPSS 0.6%CVE-2016-15056HIGHUbee EVW3226 Unauthenticated Backup File DisclosureEPSS 0.6%CVE-2020-37104HIGHASTPP 4.0.1 VoIP Billing - Database Backup DownloadEPSS 0.6%CVE-2022-44623MEDIUMIn JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settingsEPSS 0.6%CVE-2019-25706HIGHAcross DR-810 ROM-0 Unauthenticated File DisclosureEPSS 0.5%CVE-2024-47579MEDIUMMultiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)EPSS 0.5%CVE-2026-23838HIGHTandoor Recipes module allows SQLite database to be externally accessible with the default settingsEPSS 0.5%CVE-2024-47580MEDIUMMultiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)EPSS 0.5%CVE-2024-6880MEDIUMCSRF in MegaBIPEPSS 0.5%CVE-2026-49298HIGHApache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line ArgumentsEPSS 0.5%CVE-2025-0194MEDIUMInsertion of Sensitive Information into Externally-Accessible File or Directory in GitLabEPSS 0.5%CVE-2022-26329LOWFile existence disclosue vulnerability in IDM pluginEPSS 0.5%CVE-2021-3709MEDIUMApport file permission bypass through emacs byte compilation errorsEPSS 0.5%CVE-2026-15574HIGHVllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug defaultEPSS 0.4%CVE-2024-22045HIGHA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information intoEPSS 0.4%CVE-2025-31550MEDIUMWordPress WP-LESS plugin <= 1.9.6 - Sensitive Data Exposure vulnerabilityEPSS 0.4%