Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-43538LOWA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, mEPSS 3.0%CVE-2023-40278HIGHAn issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsEPSS 3.0%CVE-2023-47643LOWSuiteCRM has Unauthenticated Graphql Introspection EnabledEPSS 3.0%CVE-2021-22916—In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblockEPSS 3.0%CVE-2023-32681MEDIUMUnintended leak of Proxy-Authorization header in requestsEPSS 3.0%CVE-2026-32315MEDIUMmotionEye: World-Readable Configuration File Exposes Admin Password HashEPSS 2.9%CVE-2017-12216—A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write EPSS 2.9%CVE-2022-1595—HC Custom WP-Admin URL <= 1.4 - Unauthenticated Secret URL DisclosureEPSS 2.9%CVE-2024-3656HIGHKeycloak: unguarded admin rest api endpoints allows low privilege users to use administrative functionalitiesEPSS 2.9%CVE-2017-16607—This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. AuthEPSS 2.8%CVE-2022-21296MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that EPSS 2.8%CVE-2021-28544—Apache Subversion SVN authz protected copyfrom paths regressionEPSS 2.8%CVE-2011-0737MEDIUMAdobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveEPSS 2.8%CVE-2019-6572—A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor PaneEPSS 2.7%CVE-2020-15086CRITICALPotential Remote Code Execution in TYPO3 with mediace extensionEPSS 2.7%CVE-2024-31816HIGHIn TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizEPSS 2.7%CVE-2017-6646—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2017-6645—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2017-6642—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2017-6643—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%