Falhas do tipo CWE-1230

26 resultados

Implementação inadequada de segurança

É uma fraqueza genérica que descreve quando um mecanismo de segurança foi implementado, mas de forma insuficiente ou incorreta para realmente proteger contra a ameaça que deveria bloquear. O código tenta se defender, mas a defesa é furada: validações incompletas, lógica de controle de acesso quebrada, ou criptografia mal aplicada.

Exemplo

Um sistema implementa autenticação por token, mas valida apenas se o token existe—sem verificar assinatura, validade ou se foi revogado. Qualquer token forjado passa. Ou um filtro de SQL injection que remove apenas a palavra 'UNION', permitindo 'Un/**/ion'.

Como mitigar

Use bibliotecas e frameworks de segurança bem estabelecidas em vez de reinventar a roda. Faça revisão de código focada em segurança, com checklist explícito (validação em entrada, saída, lógica de autorização, criptografia). Teste com casos adversariais: tente contornar suas próprias defesas.

CVE-2023-1974HIGHExposure of Sensitive Information Through Metadata in answerdev/answerEPSS 0.6%CVE-2024-9447MEDIUMExposure of Sensitive Information in transformeroptimus/superagiEPSS 0.6%CVE-2024-9099HIGHExposure of Private API Keys in lunary-ai/lunaryEPSS 0.5%CVE-2025-0330HIGHExposure of Sensitive Information in berriai/litellmEPSS 0.5%CVE-2023-6962MEDIUMWP Meta SEO <= 4.5.12 - Information Exposure via Meta DescriptionEPSS 0.4%CVE-2024-47517MEDIUMExpired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM accessEPSS 0.4%CVE-2026-49270MEDIUMApache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)EPSS 0.4%CVE-2025-26527MEDIUMNon-searchable tags can still be discovered on the tag search page and in the tags blockEPSS 0.3%CVE-2023-32488MEDIUM Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially EPSS 0.3%CVE-2025-1921MEDIUMInappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about aEPSS 0.3%CVE-2024-8910MEDIUMHT Mega – Absolute Addons For Elementor <= 2.6.5 - Authenticated (Contributor+) Sensitive Information Exposure via template_idEPSS 0.3%CVE-2026-29055MEDIUMTandoor Recipes: WebP and GIF Image Uploads Bypass EXIF/Metadata Stripping, Leaking GPS Coordinates and PIIEPSS 0.3%CVE-2024-53291HIGHDell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attaEPSS 0.3%CVE-2025-48941MEDIUMMyBB may disclosure unviewable threads' titles in searchesEPSS 0.3%CVE-2024-49395MEDIUMMutt: neomutt: bcc email header field is indirectly leaked by cryptographic info blockEPSS 0.3%CVE-2026-14351MEDIUMExposure of Sensitive Information Through Metadata in GitLabEPSS 0.3%CVE-2025-13084MEDIUMOpto 22 groov View Exposure of Sensitive Information Through MetadataEPSS 0.3%CVE-2024-10324MEDIUMRomethemeKit For Elementor <= 1.5.2 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.3%CVE-2026-27661MEDIUMA vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential informatiEPSS 0.3%CVE-2026-45544MEDIUMNextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewServiceEPSS 0.2%