Falhas do tipo CWE-200

4.974 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-44431HIGHurllib3: Sensitive headers forwarded across origins in proxied low-level redirectsEPSS 0.3%CVE-2026-88059MEDIUMAngular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`EPSS 0.3%CVE-2026-64778MEDIUMThe issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26EPSS 0.3%CVE-2026-62286MEDIUMDozzle label filters do not restrict container event and statistics streamsEPSS 0.3%CVE-2023-24010HIGHData Distribution Service (DDS) Chain of Trust (CoT) violation in Fast DDSEPSS 0.3%CVE-2024-23207MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 1EPSS 0.3%CVE-2026-91766MEDIUMCross-origin credential leak in HTTP stream wrapper redirectsEPSS 0.3%CVE-2026-100418MEDIUMFlame through 2.4.0 Information Exposure via GET /api/configEPSS 0.3%CVE-2023-24011HIGHData Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Cyclone DDSEPSS 0.3%CVE-2025-5064MEDIUMInappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin EPSS 0.3%CVE-2025-54290MEDIUMProject Existence Disclosure via Error Handling in LXD Image ExportEPSS 0.3%CVE-2026-71087MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.3%CVE-2026-70911MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2026-46790MEDIUMVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that EPSS 0.3%CVE-2026-60260MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2026-60237MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.3%CVE-2026-46841MEDIUMVulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitableEPSS 0.3%CVE-2026-60156MEDIUMVulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulneraEPSS 0.3%CVE-2026-46830MEDIUMVulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitablEPSS 0.3%CVE-2024-27897HIGHInput verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.3%