Falhas do tipo CWE-1336

254 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, tokens, arquivos internos, estrutura do sistema) a usuários ou atacantes que não deveriam acessá-los. Isso ocorre por falta de controle de acesso adequado, validação insuficiente ou exposição acidental de dados em logs, mensagens de erro ou respostas HTTP.

Exemplo

Um site exibe mensagens de erro detalhadas que revelam caminhos de arquivos e versões de banco de dados; ou uma API retorna dados de outros usuários porque não valida permissões; ou credenciais ficam expostas em comentários do código-fonte publicado.

Como mitigar

Implemente controle de acesso granular (verificar quem acessa o quê); sanitize mensagens de erro (mostrar genéricas ao usuário, logs detalhados apenas internamente); revise e restrinja dados retornados por APIs; escaneie repositórios e logs de produção para credenciais expostas.

CVE-2023-27995HIGHA improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an auEPSS 1.1%CVE-2026-22244HIGHOpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEEPSS 1.1%CVE-2024-32406HIGHServer-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code viaEPSS 1.1%CVE-2025-67843HIGHA Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attacEPSS 1.1%CVE-2026-40478CRITICALImproper neutralization of specific syntax patterns for unauthorized expressions in ThymeleafEPSS 1.1%CVE-2023-2259CRITICALImproper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.ioEPSS 1.1%CVE-2026-28697CRITICALCraft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig TemplatesEPSS 1.1%CVE-2024-37301HIGHdocument-merge-service vulnerable to Remote Code Execution via Server-Side Template InjectionEPSS 1.0%CVE-2023-6709CRITICALImproper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflowEPSS 0.9%CVE-2026-21448HIGHBagisto has Normal & Blind SSTI from low-privilege user when ordering productEPSS 0.9%CVE-2025-68454MEDIUMCraft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTIEPSS 0.9%CVE-2026-94109HIGHopenEQUELLA < 2026.1.0 Authenticated Stored SSTI via FreemarkerPortletRendererEPSS 0.9%CVE-2021-4315MEDIUMNYUCCL psiTurk experiment.py special elements used in a template engineEPSS 0.9%CVE-2025-32461CRITICALwikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are EPSS 0.9%CVE-2026-25526CRITICALJinJava Bypass through ForTag leads to Arbitrary Java ExecutionEPSS 0.9%CVE-2025-62369HIGHXibo CMS: Remote Code Execution through module templatesEPSS 0.9%CVE-2025-57811MEDIUMCraft Potential Remote Code Execution via Twig SSTIEPSS 0.9%CVE-2024-42355HIGHShopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagEPSS 0.9%CVE-2024-25624MEDIUMiris-web vulnerable to Server Side Template Injection in reportsEPSS 0.9%CVE-2026-40477CRITICALImproper restriction of the scope of accessible objects in Thymeleaf expressionsEPSS 0.9%