Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2021-41532—Unauthenticated access to Ozone Recon HTTP endpointsEPSS 2.4%CVE-2026-2262HIGHEasy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 2.4%CVE-2021-39856MEDIUMAdobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via LoadFileEPSS 2.4%CVE-2021-39855MEDIUMAdobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via src ParameterEPSS 2.4%CVE-2025-9209CRITICALRestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWTEPSS 2.3%CVE-2025-12139HIGHFile Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information ExposureEPSS 2.3%CVE-2017-6626—A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allowEPSS 2.3%CVE-2020-8216—An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting detailsEPSS 2.3%CVE-2018-0245—A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote EPSS 2.3%CVE-2026-34472HIGHUnauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attacEPSS 2.3%CVE-2024-12008MEDIUMW3 Total Cache <= 2.8.1 Information Exposure via Log FilesEPSS 2.3%CVE-2021-21323MEDIUMRegression in DNS leakage from Tor windowsEPSS 2.3%CVE-2017-12354—A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to viEPSS 2.2%CVE-2024-8929MEDIUMLeak partial content of the heap through heap buffer over-read in mysqlndEPSS 2.2%CVE-2026-4020HIGHGravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 2.2%CVE-2020-15098HIGHMissing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMSEPSS 2.2%CVE-2022-23633HIGHExposure of sensitive information in Action PackEPSS 2.2%CVE-2020-8151—There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requestEPSS 2.2%CVE-2020-3411HIGHCisco DNA Center Information Disclosure VulnerabilityEPSS 2.2%CVE-2023-28322MEDIUMAn information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callbackEPSS 2.2%