Fallos del tipo CWE-668

235 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, dados pessoais, internals do sistema) através de canais ou comportamentos não pretendidos. O risco é que um atacante ou usuário não autorizado acesse informações que deveria estar protegidas, comprometendo confidencialidade.

Ejemplo

Uma API retorna stack traces completos em erros HTTP, revelando caminhos internos do servidor e bibliotecas usadas. Um atacante captura essa resposta e usa as informações para identificar versões vulneráveis e planejar exploits mais direcionados.

Cómo mitigar

Implemente tratamento de erros genérico (nunca exponha detalhes técnicos ao usuário final), use logging seguro para diagnóstico interno, aplique princípio do menor privilégio em acesso a dados, e realize auditorias regulares de o que sua aplicação expõe em respostas, logs e comentários de código.

CVE-2023-27976HIGH A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a maliEPSS 0.8%CVE-2022-38599MEDIUMTeleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web iEPSS 0.8%CVE-2022-39015Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.EPSS 0.8%CVE-2021-30153MEDIUMAn issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisEPSS 0.8%CVE-2023-45911CRITICALAn issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.EPSS 0.8%CVE-2026-44009CRITICALvm2: Sandbox Breakout Through Null Proto ExceptionEPSS 0.8%CVE-2023-25409HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to other users outlets.EPSS 0.8%CVE-2023-37911MEDIUMorg.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documentsEPSS 0.8%CVE-2022-45895MEDIUMPlanet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx inEPSS 0.7%CVE-2019-1848CRITICALCisco DNA Center Authentication Bypass VulnerabilityEPSS 0.7%CVE-2024-22281HIGHApache Helix Front (UI): Helix front hard-coded secret in the express-sessionEPSS 0.7%CVE-2020-12142MEDIUMIPSec UDP key material can be retrieved from EdgeConnect by a user with admin credentialsEPSS 0.7%CVE-2022-2882MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 beforeEPSS 0.7%CVE-2020-22647CRITICALAn issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.EPSS 0.7%CVE-2026-34538MEDIUMApache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)EPSS 0.7%CVE-2020-15215MEDIUMContext isolation bypass in ElectronEPSS 0.7%CVE-2026-28779HIGHApache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applicationsEPSS 0.7%CVE-2026-54504HIGHMCP Documentation Server: Web UI API binds to all interfaces without authentication by defaultEPSS 0.7%CVE-2026-45077HIGHSymfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log ListenerEPSS 0.7%CVE-2022-44310HIGHIn Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived sharEPSS 0.7%