Falhas do tipo CWE-200

4.953 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-28434MEDIUMcpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response headerEPSS 0.4%CVE-2025-12276MEDIUMLearnHouse Image information disclosureEPSS 0.4%CVE-2024-3505MEDIUMJFrog Self-Hosted Artifactory Proxy configuration accessible to low-privilege usersEPSS 0.4%CVE-2026-90541MEDIUMWWBN AVideo Unauthenticated Information Disclosure via menus.json.phpEPSS 0.4%CVE-2026-53912MEDIUMCerebrate self-registration password hash exposure via inbox and audit log viewsEPSS 0.4%CVE-2026-57897MEDIUMCross-Repo Information Disclosure via Org-Level Actions Run/Job APIsEPSS 0.4%CVE-2026-9545HIGHexposing HTTP/3 early dataEPSS 0.4%CVE-2024-3228MEDIUMSocial Sharing Plugin – Kiwi <= 2.1.7 - Information DisclosureEPSS 0.4%CVE-2026-6346HIGHSensitive credentials exposed in plaintext in Mattermost support packetsEPSS 0.4%CVE-2026-27193HIGHFeathers exposes internal headers via unencrypted session cookieEPSS 0.4%CVE-2025-63209HIGHThe ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and possibly other models,EPSS 0.4%CVE-2024-8899MEDIUMJeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_templateEPSS 0.4%CVE-2026-54673HIGHelectron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`EPSS 0.4%CVE-2026-33677MEDIUMWebhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via APIEPSS 0.4%CVE-2026-76712HIGHUnauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)EPSS 0.4%CVE-2023-47799HIGHMahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administratEPSS 0.4%CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2022-41913MEDIUMDiscourse-calendar exposes members of hidden groupsEPSS 0.4%CVE-2026-42223MEDIUMnginx-ui: Settings API Exposes Protected SecretsEPSS 0.4%CVE-2026-30829MEDIUMCheckmate: Unauthenticated Access to Unpublished Status PageEPSS 0.4%