Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2017-6645—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2017-6643—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2026-5032HIGHW3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent HeaderEPSS 2.7%CVE-2014-0786—Ecava IntegraXor Information ExposureEPSS 2.6%CVE-2023-39508HIGHApache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledgesEPSS 2.6%CVE-2026-39363HIGHVite Affected by Arbitrary File Read via Vite Dev Server WebSocketEPSS 2.6%CVE-2018-0288—A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access sensitive data about EPSS 2.6%CVE-2004-2320MEDIUMThe default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13EPSS 2.6%CVE-2022-24853MEDIUMFile system exposure in MetabaseEPSS 2.5%CVE-2026-27886CRITICALStrapi may leak sensitive data via relational filtering due to lack of query sanitizationEPSS 2.5%CVE-2021-39857MEDIUMAdobe Acrobat Reader DC Information Disclosure via ActiveX LoadFileEPSS 2.5%CVE-2022-1077MEDIUMTEM FLEX-1080/FLEX-1085 Log information disclosureEPSS 2.5%CVE-2022-22547—Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted EPSS 2.5%CVE-2018-16876LOWansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leEPSS 2.5%CVE-2026-41492CRITICALUnauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in DgraphEPSS 2.5%CVE-2022-0725—A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information ExpoEPSS 2.5%CVE-2023-32561HIGHA previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authenticaEPSS 2.4%CVE-2019-7619—Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated aEPSS 2.4%CVE-2014-2347—AMTELCO miSecure Information ExposureEPSS 2.4%CVE-2024-1209MEDIUMLearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignmentsEPSS 2.4%