Falhas do tipo CWE-1336

254 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, tokens, arquivos internos, estrutura do sistema) a usuários ou atacantes que não deveriam acessá-los. Isso ocorre por falta de controle de acesso adequado, validação insuficiente ou exposição acidental de dados em logs, mensagens de erro ou respostas HTTP.

Exemplo

Um site exibe mensagens de erro detalhadas que revelam caminhos de arquivos e versões de banco de dados; ou uma API retorna dados de outros usuários porque não valida permissões; ou credenciais ficam expostas em comentários do código-fonte publicado.

Como mitigar

Implemente controle de acesso granular (verificar quem acessa o quê); sanitize mensagens de erro (mostrar genéricas ao usuário, logs detalhados apenas internamente); revise e restrinja dados retornados por APIs; escaneie repositórios e logs de produção para credenciais expostas.

CVE-2025-49828HIGHConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Remote Code ExecutionEPSS 2.1%CVE-2023-34252HIGHGrav Server-side Template Injection via Insufficient Validation in filterFilterEPSS 2.1%CVE-2023-34253HIGHGrav vulnerable to Server-side Template Injection (SSTI) via Denylist BypassEPSS 2.1%CVE-2023-2017HIGHImproper Control of Generation of Code in Twig Rendered Views in ShopwareEPSS 2.1%CVE-2026-28496CRITICALFOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCEEPSS 1.9%CVE-2021-39128HIGHAffected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA AdministrEPSS 1.9%CVE-2025-1040HIGHServer-Side Template Injection (SSTI) in significant-gravitas/autogptEPSS 1.7%CVE-2025-49136CRITICALlistmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege userEPSS 1.5%CVE-2023-46245HIGHKimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig FileEPSS 1.5%CVE-2025-46731HIGHCraft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTIEPSS 1.4%CVE-2022-0896HIGHImproper Neutralization of Special Elements Used in a Template Engine in microweber/microweberEPSS 1.4%CVE-2026-21450HIGHBagisto has SSTI in parameter that can lead to RCEEPSS 1.4%CVE-2024-12583CRITICALDynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template InjectionEPSS 1.4%CVE-2023-29297CRITICALAdmin-to-admin stored XSS via cache poisoningEPSS 1.4%CVE-2024-45053CRITICALRemote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating EngineEPSS 1.3%CVE-2023-6743HIGHUnlimited Elements for Elementor <= 1.5.89 - Authenticated(Contributor+) Remote Code Execution via template importEPSS 1.3%CVE-2026-73299CRITICALPrompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks RendererEPSS 1.2%CVE-2026-27641CRITICALFlask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template InjectionEPSS 1.2%CVE-2024-41950HIGHInsecure Jinja2 templates rendered in Haystack Components can lead to RCEEPSS 1.2%CVE-2024-30372HIGHAllegra getLinkText Server-Side Template Injection Remote Code Execution VulnerabilityEPSS 1.2%