Falhas do tipo CWE-200

4.909 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2019-10195MEDIUMA flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way thEPSS 1.8%CVE-2022-43684CRITICALACL bypass in Reporting functionalityEPSS 1.8%CVE-2021-20313—A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is poEPSS 1.8%CVE-2017-2609MEDIUMjenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autoEPSS 1.8%CVE-2018-1052—Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read aEPSS 1.8%CVE-2021-41082HIGHPrivate message title and participating users leaked in discourseEPSS 1.8%CVE-2025-26667MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.8%CVE-2024-21136HIGHVulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are aEPSS 1.8%CVE-2020-11021MEDIUMHTTP request which redirect to another hostname do not strip authorization header in Actions Http-ClientEPSS 1.8%CVE-2019-10223MEDIUMA security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 releasEPSS 1.8%CVE-2020-15099HIGHExposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMSEPSS 1.8%CVE-2019-10156MEDIUMA flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of EPSS 1.8%CVE-2016-7061LOWAn information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuEPSS 1.8%CVE-2016-6542—The MAC address/device tracking ID of an iTrack Easy can be obtained within range of the deviceEPSS 1.7%CVE-2026-32596HIGHGlances exposes the REST API without authenticationEPSS 1.7%CVE-2025-32395MEDIUMVite has an `server.fs.deny` bypass with an invalid `request-target`EPSS 1.7%CVE-2021-27434—Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework verEPSS 1.7%CVE-2018-0105—A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitiEPSS 1.7%CVE-2017-6614—A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authentiEPSS 1.7%CVE-2018-14803—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that couldEPSS 1.7%