Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2026-39884HIGHMCP Server Kubernetes has Argument Injection in its port_forward tool via space-splittingEPSS 0.3%CVE-2026-7725MEDIUMPrefectHQ prefect GitRepository Pull storage.py argument injectionEPSS 0.2%CVE-2022-20930MEDIUMCisco SD-WAN Software Arbitrary File Corruption VulnerabilityEPSS 0.2%CVE-2026-8773MEDIUMlinlinjava litemall Database Setting DbUtil.java load argument injectionEPSS 0.2%CVE-2026-52817HIGHLinuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow privilege escalationEPSS 0.2%CVE-2026-25690MEDIUMAn improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through EPSS 0.2%CVE-2026-18157HIGHYggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injectionEPSS 0.2%CVE-2026-78678HIGHGitPython before 3.1.59 Arbitrary File Read via Repo.blame()EPSS 0.2%CVE-2026-87818HIGHGitPython 3.1.59 Local File Content Oracle via --no-indexEPSS 0.2%CVE-2026-54085HIGHWazuh: Missing input validation in multiple active response scripts allows argument injectionEPSS 0.2%CVE-2026-41013HIGHTenant-controlled comma smuggles arbitrary CIFS mount optionsEPSS 0.2%CVE-2026-23924MEDIUMAgent 2 Docker plugin arbitrary file read via Docker API injectionEPSS 0.2%CVE-2026-74237HIGHGFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf ClientEPSS 0.2%CVE-2026-3682MEDIUMwelovemedia FFmate ffmpeg.go Execute argument injectionEPSS 0.2%CVE-2026-40113HIGHPraisonAI has an Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-varsEPSS 0.2%CVE-2026-90467MEDIUMaiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addressesEPSS 0.2%CVE-2023-22632LOWPRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.EPSS 0.2%CVE-2023-22631LOWPRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.EPSS 0.2%CVE-2026-11332HIGHAnsible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionEPSS 0.2%CVE-2026-79685MEDIUMDell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vEPSS 0.2%