Fallos del tipo CWE-93

207 resultados

Divulgação de Informações

Uma fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, IPs, estrutura interna) a atores não autorizados, seja através de mensagens de erro verbosas, logs acessíveis, respostas HTTP malformadas ou canais inseguros. O risco está em fornecer inteligência ao atacante para explorar outros vetores.

Ejemplo

Um servidor Java expõe stack traces completos em páginas de erro 500, revelando caminhos internos, versões de bibliotecas e nomes de bancos de dados; ou uma API retorna tokens JWT em plaintext em queries de URL em vez de headers, sendo capturados por proxy ou histórico do navegador.

Cómo mitigar

Implemente tratamento genérico de exceções (não exponha detalhes técnicos ao cliente), sanitize mensagens de erro, configure logs fora do escopo público, use HTTPS obrigatório, e revise respostas HTTP quanto a dados sensíveis. Em produção, desabilite debug mode e verbose error messages.

CVE-2023-26130HIGHVersions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the contEPSS 1.1%CVE-2018-12477LOWobs-service-refresh_patches can be tricked into deleting '..' or other unrelated directoriesEPSS 1.1%CVE-2026-82854CRITICALNodemailer before 8.0.3 SMTP Command Injection via envelope.sizeEPSS 1.1%CVE-2023-23936MEDIUMCRLF Injection in Nodejs ‘undici’ via hostEPSS 1.1%CVE-2026-30227MEDIUMMimeKit: CRLF Injection in Quoted Local-Part Enables SMTP Command Injection and Email ForgeryEPSS 1.1%CVE-2026-42578LOWNetty: HTTP Header Injection via HttpProxyHandler Disabled ValidationEPSS 1.1%CVE-2023-38551HIGHA CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code onEPSS 1.0%CVE-2026-39849HIGHPi-hole FTL remote code execution via newline injection in dns.interface configurationEPSS 1.0%CVE-2023-49082MEDIUMaiohttp's ClientSession is vulnerable to CRLF injection via methodEPSS 0.9%CVE-2024-51981MEDIUMUnauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and Toshiba Tec, and Konica Minolta, Inc.EPSS 0.9%CVE-2026-57281HIGHJenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions mEPSS 0.9%CVE-2020-3246MEDIUMCisco Umbrella Carriage Return Line Feed Injection VulnerabilityEPSS 0.9%CVE-2020-15111MEDIUMCRLF vulnerability in FiberEPSS 0.9%CVE-2026-35517HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline InjectionEPSS 0.9%CVE-2021-4097MEDIUMCRLF Injection in phpservermon/phpservermonEPSS 0.8%CVE-2026-15429MEDIUMPrivilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800vEPSS 0.8%CVE-2026-42258MEDIUMnet-imap: Command Injection via unvalidated Symbol inputsEPSS 0.8%CVE-2019-15616Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.EPSS 0.8%CVE-2025-27111MEDIUMEscape Sequence Injection vulnerability in Rack lead to Possible Log InjectionEPSS 0.7%CVE-2026-82853MEDIUMNodemailer before 8.0.5 SMTP Command Injection via CRLFEPSS 0.7%