Falhas do tipo CWE-200

4.940 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2022-3501LOWInformation exposure of template content due to missing check of permissionsEPSS 0.5%CVE-2022-41944LOWDiscourse users can see notifications for topics they no longer have access toEPSS 0.5%CVE-2026-30852MEDIUMCaddy: vars_regexp double-expands user input, leaking env vars and filesEPSS 0.5%CVE-2026-58157MEDIUMApache Traffic Server: Improper server-session reuse can expose data across client connectionsEPSS 0.5%CVE-2026-73304MEDIUMBudibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role UsersEPSS 0.5%CVE-2024-12896MEDIUMIntelbras VIP S4320 G2 Web Interface webCapsConfig information disclosureEPSS 0.5%CVE-2026-28962HIGHThis issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iEPSS 0.5%CVE-2026-1175MEDIUMbirkir prime GraphQL Directive graphql information exposureEPSS 0.5%CVE-2024-10050MEDIUMElementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via ShortcodeEPSS 0.5%CVE-2026-72670HIGHExposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy CredentialsEPSS 0.5%CVE-2020-11843MEDIUMPotential information leakage in administrator enabled debug modeEPSS 0.5%CVE-2026-53923MEDIUMvLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflowEPSS 0.5%CVE-2026-8033MEDIUMPicoTronica e-Clinic Healthcare System ECHS Response Header v2 information disclosureEPSS 0.5%CVE-2026-59155MEDIUMNezha Monitoring: DDNS and Notification credential exposure via unredacted list APIEPSS 0.5%CVE-2026-33981HIGHChangedetection.io Discloses Environment Variables via jq env Builtin in Include FiltersEPSS 0.5%CVE-2011-4917—In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.EPSS 0.5%CVE-2026-5601MEDIUMAcrel Electrical Prepaid Cloud Platform Backup File bin.rar information disclosureEPSS 0.5%CVE-2026-86672MEDIUMningzichun Student Management System Backup example.7z information disclosureEPSS 0.5%CVE-2026-28559MEDIUMwpForo Forum 2.4.14 Information Disclosure via Global RSS FeedEPSS 0.5%CVE-2025-6980HIGHCaptive Portal can expose sensitive informationEPSS 0.5%