Falhas do tipo CWE-200

4.942 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-69224MEDIUMinformation disclosure vulnerability in Esri Portal for ArcGISEPSS 0.5%CVE-2026-5413MEDIUMNewgen OmniDocs GetWebApiConfiguration information disclosureEPSS 0.5%CVE-2026-40965CRITICALCloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC EPSS 0.5%CVE-2021-37939—It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, whichEPSS 0.5%CVE-2022-45167MEDIUMAn issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to access the profiEPSS 0.5%CVE-2025-58445MEDIUMAtlantis Exposes Service Version Publicly on /status API EndpointEPSS 0.5%CVE-2026-18673MEDIUMKong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authenticationEPSS 0.5%CVE-2026-45286MEDIUMNextcloud: Calendar app leaked user identifiers via attendee suggestion endpointEPSS 0.5%CVE-2024-11090MEDIUMMembership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.5%CVE-2023-22813LOWDevice API endpoint missing access controls on Western Digital Mobile and Web AppsEPSS 0.5%CVE-2024-11290MEDIUMMember Access <= 1.1.6 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.5%CVE-2024-24748MEDIUMDisclosure of the existence of secret subcategories in DiscourseEPSS 0.5%CVE-2022-23490MEDIUMImproper access control to polling votesEPSS 0.5%CVE-2023-45809LOWDisclosure of user names via admin bulk action views in wagtailEPSS 0.5%CVE-2024-31490MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1EPSS 0.5%CVE-2024-0708MEDIUMLanding Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.2 - Unauthenticated Information ExposureEPSS 0.5%CVE-2025-10952MEDIUMgeyang ml-logger File server.py stream_handler information disclosureEPSS 0.5%CVE-2024-42351MEDIUMPossible Data Tampering & Loss of Public Datasets in GalaxyEPSS 0.5%CVE-2026-59216HIGHOpen WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_idEPSS 0.5%CVE-2024-24867MEDIUMWordPress WP Stats Manager plugin <= 6.9.4 - Sensitive Data Exposure vulnerabilityEPSS 0.5%