Fallos del tipo CWE-538

93 resultados

Exposição de informações sensíveis em arquivos ou diretórios acessíveis externamente

O aplicativo escreve dados sensíveis (senhas, tokens, chaves, dados pessoais) em arquivos ou diretórios que podem ser acessados por usuários não autorizados — seja via web, sistema de arquivos aberto, ou backup público. O risco é que um atacante leia esses arquivos e obtenha credenciais, dados privados ou material para escalar privilégios.

Ejemplo

Um sistema de e-commerce salva recibos com CPF, email e número de cartão (mascarado ou não) em um diretório /tmp/receipts acessível via HTTP; ou um desenvolvedor commita arquivo .env com credenciais de banco de dados no repositório público do GitHub.

Cómo mitigar

Nunca escreva dados sensíveis em arquivos compartilhados, públicos ou versionáveis; use variáveis de ambiente, cofres de secrets (como HashiCorp Vault), ou gestores de credenciais. Se necessário armazenar localmente, restrinja permissões de arquivo (chmod 600), criptografe o conteúdo e não exponha o diretório em URLs acessíveis.

CVE-2022-4318HIGHCri-o: /etc/passwd tampering privescEPSS 0.3%CVE-2022-20864MEDIUMCisco IOS XE ROM Monitor Software for Catalyst Switches Information Disclosure VulnerabilityEPSS 0.3%CVE-2018-4847A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive informaEPSS 0.3%CVE-2022-43933MEDIUMconfiguration secrets are logged in support-saveEPSS 0.3%CVE-2025-68429HIGHStorybook manager bundle may expose environment variables during buildEPSS 0.3%CVE-2026-50565MEDIUMFission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder containerEPSS 0.3%CVE-2026-33705MEDIUMChamilo LMS has unauthenticated access to Twig template source files exposes application logicEPSS 0.2%CVE-2025-8452MEDIUMUnauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., Toshiba Tec, and Konica Minolta, Inc.EPSS 0.2%CVE-2026-12762MEDIUMInsertion of Sensitive Information into Externally-Accessible File in IBM Business Automation InsightsEPSS 0.2%CVE-2026-21672HIGHA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.EPSS 0.2%CVE-2022-0013MEDIUMCortex XDR Agent: File Information Exposure Vulnerability When Generating Support FileEPSS 0.2%CVE-2026-5434MEDIUMImproper storage of sensitive informationEPSS 0.2%CVE-2024-31954HIGHAn issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directoEPSS 0.2%CVE-2019-25717MEDIUMDräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File DisclosureEPSS 0.2%CVE-2026-29114LOWA vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and EPSS 0.2%CVE-2025-46820HIGHphpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifactEPSS 0.2%CVE-2025-12699MEDIUMZOLL ePCR IOS Mobile Application Insertion of Sensitive Information into Externally-Accessible File or DirectoryEPSS 0.2%CVE-2023-38558MEDIUMA vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration ConsoleEPSS 0.2%CVE-2026-50099MEDIUMNaxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directoryEPSS 0.2%CVE-2026-57442MEDIUMMCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nestedEPSS 0.2%