Falhas do tipo CWE-200

4.976 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-30118LOWHCL Connections is susceptible to a sensitive information disclosure vulnerabilityEPSS 0.3%CVE-2026-22600CRITICALOpenProject is Vulnerable to Arbitrary File Read via ImageMagick SVG CoderEPSS 0.3%CVE-2025-13439MEDIUMFancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Information Disclosure and PHAR Deserialization via 'url' ParameterEPSS 0.3%CVE-2024-42337MEDIUMCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2023-22875HIGHIBM Security QRadar SIEM information disclosureEPSS 0.3%CVE-2021-20332MEDIUMMongoDB Rust Driver may publish events containing authentication-related data to a connection pool event listener configured by an applicationEPSS 0.3%CVE-2022-31066MEDIUMConfiguration API in EdgeXFoundry exposes message bus credentials to local unauthenticated usersEPSS 0.3%CVE-2024-32385MEDIUMAn issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a EPSS 0.3%CVE-2022-45459LOWSensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before bEPSS 0.3%CVE-2024-9542MEDIUMSky Addons for Elementor <= 2.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Content Switcher Widget Elementor TemplateEPSS 0.3%CVE-2026-54317HIGHHome Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANEPSS 0.3%CVE-2024-8494MEDIUMElementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via ShortcodeEPSS 0.3%CVE-2026-54276MEDIUMAIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect ChallengesEPSS 0.3%CVE-2026-61267HIGHVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versEPSS 0.3%CVE-2023-24588MEDIUMExposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticateEPSS 0.3%CVE-2024-45391HIGHTina search token leak via lock file in TinaCMSEPSS 0.3%CVE-2026-75839MEDIUMArcadeDB before 26.8.1 Information Disclosure via Cluster EndpointsEPSS 0.3%CVE-2026-91981MEDIUMVikunja before 2.6.0 User Enumeration via v2 APIEPSS 0.3%CVE-2026-48210MEDIUMPossible information disclosure via External InterfaceEPSS 0.3%CVE-2026-65009MEDIUMOpenRemote before 1.26.2 Information Disclosure via Syslog REST APIEPSS 0.3%