Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2023-26310HIGHCommand Injection In OPPO ServiceEPSS 1.1%CVE-2024-3684HIGHImproper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management ConsoleEPSS 1.1%CVE-2026-22738CRITICALSpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code ExecutionEPSS 1.1%CVE-2024-23731CRITICALThe OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function arguEPSS 1.1%CVE-2026-86060CRITICALSSH session privilege manipulation via a crafted username in Mikrotik RouterOSEPSS 1.1%KEVCVE-2025-35010HIGHMicrohard Bullet-LTE and IPn4Gii AT+MNPINGTM Argument InjectionEPSS 1.0%CVE-2025-35009HIGHMicrohard Bullet-LTE and IPn4Gii AT+MNNETSP Argument InjectionEPSS 1.0%CVE-2025-35006HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFPORTFWD Argument InjectionEPSS 1.0%CVE-2025-35008HIGHMicrohard Bullet-LTE and IPn4Gii AT+MMNAME Argument InjectionEPSS 1.0%CVE-2025-35005HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFMAC Argument InjectionEPSS 1.0%CVE-2025-35007HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFRULE Argument InjectionEPSS 1.0%CVE-2025-35004HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFIP Argument InjectionEPSS 1.0%CVE-2022-47502Apache OpenOffice: Macro URL arbitrary script executionEPSS 1.0%CVE-2026-57572CRITICALCrawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_argsEPSS 0.9%CVE-2025-3460HIGHON Semiconductor Quantenna set_tx_pow Argument InjectionEPSS 0.9%CVE-2025-48385HIGHGit alllows arbitrary file writes via bundle-uri parameter injectionEPSS 0.9%CVE-2024-35307CRITICALArgument Injection Leading to Remote Code Execution in Realtime Graph ExtensionEPSS 0.9%CVE-2022-1399CRITICALRemote code execution in scheduled tasks componentEPSS 0.9%CVE-2024-47516CRITICALPagure: argument injection in pagurerepo.log()EPSS 0.9%CVE-2026-6951CRITICALVersions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912]EPSS 0.9%