Falhas do tipo CWE-200

4.939 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-23935LOWPresence of restricted personal Discourse messages may be leaked if tagged with a tag EPSS 0.5%CVE-2022-42132MEDIUMThe Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix packEPSS 0.5%CVE-2026-64684MEDIUMRMCP: Custom HTTP headers leak to cross-origin redirect targetsEPSS 0.5%CVE-2025-20221MEDIUMA vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass LEPSS 0.5%CVE-2023-47393—An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of other users and access sEPSS 0.5%CVE-2023-49278MEDIUMUmbraco CMS brute force exploit can be used to collect valid usernamesEPSS 0.5%CVE-2026-25199CRITICALApache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance AccessEPSS 0.5%CVE-2024-39344HIGHAn issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is instaEPSS 0.5%CVE-2024-24215MEDIUMAn issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information vEPSS 0.5%CVE-2023-47392—An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted addEPSS 0.5%CVE-2024-13611HIGHBetter Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2023-38503MEDIUMDirectus has Incorrect Permission Checking for GraphQL SubscriptionsEPSS 0.5%CVE-2022-24725MEDIUMExposure of home directory through shescape on Unix with BashEPSS 0.5%CVE-2025-23047MEDIUMCilium vulnerable to information leakage via insecure default Hubble UI CORS headerEPSS 0.5%CVE-2024-13600HIGHMajestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.0.5 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2026-92916HIGHGrav through 2.0.21 Unauthenticated Information Disclosure via ClockworkEPSS 0.5%CVE-2025-54304CRITICALAn issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is startEPSS 0.5%CVE-2024-26309MEDIUMArcher Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker cEPSS 0.5%CVE-2023-5552HIGHA password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in SophEPSS 0.5%CVE-2023-50271HIGHHP-UX System Management Homepage, Disclosure of InformationEPSS 0.5%