Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2026-0304MEDIUMCortex XDR Broker VM: Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-59433MEDIUM@conventional-changelog/git-client has an Argument Injection vulnerabilityEPSS 0.2%CVE-2025-43730HIGHDell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument InjectionEPSS 0.2%CVE-2026-35153MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.2%CVE-2026-24739MEDIUMSymfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operationsEPSS 0.2%CVE-2026-73621MEDIUMGitPython before 3.1.56 Arbitrary File Truncation via Commit.countEPSS 0.2%CVE-2026-14459HIGHArgument Injection in TUBITAK BILGEM's pardus-softwareEPSS 0.2%CVE-2026-86862HIGHpgAdmin 4: Connection-string injection via the database field in the Restore and Maintenance toolsEPSS 0.2%CVE-2026-43698HIGHAn injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 1EPSS 0.2%CVE-2026-44968MEDIUMdbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type ParametersEPSS 0.2%CVE-2025-36565MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 releasEPSS 0.2%CVE-2026-15793MEDIUMGit source checkout from a bundle file could lead to command injectionEPSS 0.2%CVE-2026-48711HIGHSSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')EPSS 0.2%CVE-2026-55887HIGHMCP Gateway: Argument injection via OCI image label YAML in Docker MCP GatewayEPSS 0.2%CVE-2026-4145HIGHDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticatEPSS 0.2%CVE-2025-24845MEDIUMImproper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.EPSS 0.2%CVE-2026-41570HIGHPHPUnit: Argument injection via newline in PHP INI values forwarded to child processesEPSS 0.2%CVE-2026-20063MEDIUMCisco Secure FTD Software Authenticated Command Injection VulnerabilityEPSS 0.2%CVE-2026-87794HIGHbestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip DestinationEPSS 0.2%CVE-2025-6231HIGHAn improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute coEPSS 0.2%