Falhas do tipo CWE-200

4.974 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-105030MEDIUMKener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard APIEPSS 0.3%CVE-2026-58425MEDIUMOAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)EPSS 0.3%CVE-2026-58510MEDIUMGHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateEPSS 0.3%CVE-2024-41698MEDIUMPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2024-28188MEDIUMjupyter-scheduler's endpoint is missing authenticationEPSS 0.3%CVE-2026-12120MEDIUMFireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' ParameterEPSS 0.3%CVE-2026-32100MEDIUMswag/platform-security: `/api/_info/config` route exposes information about licenses and active security fixesEPSS 0.3%CVE-2026-84146MEDIUMXpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick ViewEPSS 0.3%CVE-2024-20910LOWVulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. DifficEPSS 0.3%CVE-2026-56728MEDIUMZammad: Cross-User Taskbar Item Access Control VulnerabilityEPSS 0.3%CVE-2026-78152MEDIUMSureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person SchemaEPSS 0.3%CVE-2026-80423HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.3%CVE-2026-32142MEDIUMshopware/commercial: `/api/_info/config` route exposes information about licensesEPSS 0.3%CVE-2026-1267MEDIUMIBM Planning Analytics Information DisclosureEPSS 0.3%CVE-2026-1371MEDIUMTutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX ActionEPSS 0.3%CVE-2025-13660MEDIUMGuest Support <= 1.2.3 - Unauthenticated User Email Disclosure in guest_support_handler AJAX EndpointEPSS 0.3%CVE-2026-10254MEDIUMSourceCodester Pet Grooming Management Software admin file information disclosureEPSS 0.3%CVE-2025-4390MEDIUMWP Private Content Plus <= 3.6.2 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2025-23215CRITICALPMD Designer's release key passphrase (GPG) available on Maven Central in cleartextEPSS 0.3%CVE-2026-90899HIGHJoomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0EPSS 0.3%