Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2021-31173MEDIUMMicrosoft SharePoint Server Information Disclosure VulnerabilityEPSS 2.1%CVE-2026-34474HIGHSensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interEPSS 2.1%CVE-2020-24406LOWDocument root path disclosure on Maintenance pageEPSS 2.1%CVE-2025-50738CRITICALThe Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo contEPSS 2.1%CVE-2021-30168CRITICALMERIT LILIN ENT.CO.,LTD. P2/Z2/P3/Z3 IP camera - Sensitive Data Exposure-1EPSS 2.1%CVE-2021-44702LOWAdobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) for Internet Explorer LoadFile NTLMv2 SSO Auth leak vulnerabilityEPSS 2.1%CVE-2021-44739LOWAdobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) src NTLMv2 SSO Auth leak vulnerabilityEPSS 2.1%CVE-2023-36894MEDIUMMicrosoft SharePoint Server Information Disclosure VulnerabilityEPSS 2.1%CVE-2021-20228—A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature whenEPSS 2.1%CVE-2023-6266HIGHBackup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information ExposureEPSS 2.1%CVE-2022-29165CRITICALArgo CD will blindly trust JWT claims if anonymous access is enabledEPSS 2.1%CVE-2019-0202—The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versionEPSS 2.0%CVE-2026-33829MEDIUMWindows Snipping Tool Spoofing VulnerabilityEPSS 2.0%CVE-2024-1210MEDIUMLearnDash LMS <= 4.10.1 - Sensitive Information Exposure via APIEPSS 2.0%CVE-2017-6651—A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to acEPSS 2.0%CVE-2023-40600MEDIUMWordPress EWWW Image Optimizer Plugin <= 7.2.0 is vulnerable to Sensitive Data ExposureEPSS 2.0%CVE-2021-21817HIGHAn information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially craftedEPSS 2.0%CVE-2023-29348HIGHWindows Remote Desktop Gateway (RD Gateway) Information Disclosure VulnerabilityEPSS 2.0%CVE-2023-40712—Apache Airflow: Secrets can be unmasked in the "Rendered Template" EPSS 2.0%CVE-2019-1908HIGHCisco Integrated Management Controller Information Disclosure VulnerabilityEPSS 2.0%