Falhas do tipo CWE-200

4.951 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-47176MEDIUMQuest Bot: Logging module can disclose private-channel message contents to a lower-visibility log channelEPSS 0.4%CVE-2026-53725MEDIUMParse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is deniedEPSS 0.4%CVE-2024-27113CRITICALInsecure Direct Object Reference to export Database in SOPlanning before 1.52.02EPSS 0.4%CVE-2026-47177MEDIUMQuest Bot: Ticket transcripts can disclose private ticket contents to a lower-visibility channelEPSS 0.4%CVE-2026-8965HIGHInformation disclosure in the DOM: Security componentEPSS 0.4%CVE-2026-6347HIGHMattermost Calls plugin exposes TURN server credentials in plaintext in support packetsEPSS 0.4%CVE-2023-30611MEDIUMReaction metadata exposed in private topics in Discourse-reactionsEPSS 0.4%CVE-2026-8966HIGHInformation disclosure in the IP Protection componentEPSS 0.4%CVE-2026-8967HIGHInformation disclosure in the Graphics: WebGPU componentEPSS 0.4%CVE-2024-43707HIGHKibana exposure of sensitive information to an unauthorized actorEPSS 0.4%CVE-2026-6782HIGHInformation disclosure in the IP Protection componentEPSS 0.4%CVE-2023-31416MEDIUMElastic Cloud on Kubernetes (ECK) secret token configuration issueEPSS 0.4%CVE-2026-60415HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2023-50894HIGHIn Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password EPSS 0.4%CVE-2026-17048MEDIUMKeycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest apiEPSS 0.4%CVE-2025-62604MEDIUMMeterSphere logic flaw allows retrieval of arbitrary user informationEPSS 0.4%CVE-2026-67357HIGHArcadeDB before 26.7.3 Information Disclosure via get_server_settingsEPSS 0.4%CVE-2025-13371HIGHMoney Space <= 2.13.9 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-50870HIGHAn information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitivEPSS 0.4%CVE-2024-6549MEDIUMAdmin Post Navigation <= 2.1 - Unauthenticated Full Path DisclosureEPSS 0.4%