Fallos del tipo CWE-668

235 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, dados pessoais, internals do sistema) através de canais ou comportamentos não pretendidos. O risco é que um atacante ou usuário não autorizado acesse informações que deveria estar protegidas, comprometendo confidencialidade.

Ejemplo

Uma API retorna stack traces completos em erros HTTP, revelando caminhos internos do servidor e bibliotecas usadas. Um atacante captura essa resposta e usa as informações para identificar versões vulneráveis e planejar exploits mais direcionados.

Cómo mitigar

Implemente tratamento de erros genérico (nunca exponha detalhes técnicos ao usuário final), use logging seguro para diagnóstico interno, aplique princípio do menor privilégio em acesso a dados, e realize auditorias regulares de o que sua aplicação expõe em respostas, logs e comentários de código.

CVE-2020-26261HIGHuser-readable api tokens in systemd unitsEPSS 0.5%CVE-2025-23205MEDIUM`frame-ancestors: self` grants all users access to formgrader in nbgraderEPSS 0.5%CVE-2023-39040MEDIUMAn information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.5%CVE-2026-14960CRITICALCVE-2026-14960EPSS 0.5%CVE-2023-39046MEDIUMAn information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.5%CVE-2019-9011MEDIUMIn Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.EPSS 0.4%CVE-2026-30912HIGHApache Airflow: Exposing stack trace in case of constraint errorEPSS 0.4%CVE-2022-41874LOWTauri Filesystem Scope can be Partially BypassedEPSS 0.4%CVE-2026-72764MEDIUMn8n before 1.123.67 Module Cache Poisoning via Code NodeEPSS 0.4%CVE-2026-56077HIGHPraisonAI - Information Disclosure via Shared MultiAgentLedger StateEPSS 0.4%CVE-2023-42716HIGHIn telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional executionEPSS 0.4%CVE-2023-45145LOWRedis Unix-domain socket may have be exposed with the wrong permissions for a short time window.EPSS 0.4%CVE-2022-32530MEDIUMA CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong seEPSS 0.4%CVE-2026-24473MEDIUMHono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)EPSS 0.4%CVE-2024-51754LOWUnguarded calls to __toString() when nesting an object into an array in TwigEPSS 0.4%CVE-2026-14611MEDIUMDeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resourceEPSS 0.4%CVE-2024-51755LOWUnguarded calls to __isset() and to array-accesses when the sandbox is enabled in TwigEPSS 0.4%CVE-2026-32690LOWApache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1EPSS 0.4%CVE-2026-28806CRITICALImproper authorization in device bulk actions and device update API allows cross-organization device controlEPSS 0.4%CVE-2026-53648MEDIUMFOSSBilling: Downloadable product files can be overwritten through filename collisionsEPSS 0.4%