Falhas do tipo CWE-200

4.909 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-55875CRITICALhttp4k has a potential XXE (XML External Entity Injection) vulnerabilityEPSS 1.9%CVE-2023-39337—A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier tEPSS 1.9%CVE-2025-53624CRITICALdocusaurus-plugin-content-gists Exposes GitHub Personal Access TokenEPSS 1.9%CVE-2021-3426MEDIUMThere's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to starEPSS 1.9%CVE-2026-69806HIGH.NET Elevation of Privilege VulnerabilityEPSS 1.9%CVE-2019-10217MEDIUMA flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fieldsEPSS 1.9%CVE-2021-22892—An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be dEPSS 1.9%CVE-2024-8461MEDIUMD-Link DNS-320 Web Management Interface discovery.cgi information disclosureEPSS 1.9%CVE-2020-8481CRITICALABB Central Licensing System - Information disclosureEPSS 1.9%CVE-2019-15576—An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private syEPSS 1.9%CVE-2019-6574—A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions EPSS 1.8%CVE-2017-2606MEDIUMJenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that shouEPSS 1.8%CVE-2025-59214MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 1.8%CVE-2024-38020MEDIUMMicrosoft Outlook Spoofing VulnerabilityEPSS 1.8%CVE-2019-7305MEDIUMeXtplorer exposes /usr and /etc/extplorer over HTTPEPSS 1.8%CVE-2022-39258HIGHmailcow-dockerized critical information misrepresentation can lead to phishing attacks through Swagger UIEPSS 1.8%CVE-2019-13523—In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to EPSS 1.8%CVE-2017-16539MEDIUMThe DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackeEPSS 1.8%CVE-2021-24948—The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data DisclosureEPSS 1.8%CVE-2023-45131HIGHUnauthenticated access to new private chat messages in DiscourseEPSS 1.8%