Falhas do tipo CWE-200

4.909 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2020-8210—Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile SEPSS 1.5%CVE-2025-6082MEDIUMBirth Chart Compatibility <= 2.0 - Unauthenticated Full Path ExposureEPSS 1.5%CVE-2023-38344—An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP actioEPSS 1.5%CVE-2018-10857MEDIUMgit-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annEPSS 1.5%CVE-2016-9159MEDIUMA vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPEPSS 1.5%CVE-2026-2025HIGHMail Mint < 1.19.5 - Unauthenticated Emails DisclosureEPSS 1.5%CVE-2020-35518—When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be usedEPSS 1.5%CVE-2019-13410—TOPMeeting version before version 8.8 (2019/08/19) allows an attacker to obtain sensitive informationEPSS 1.5%CVE-2023-35005—Apache Airflow: Information disclosure on configuration viewEPSS 1.5%CVE-2025-29805HIGHOutlook for Android Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-31091HIGHChange in port should be considered a change in origin in GuzzleEPSS 1.5%CVE-2017-12224—A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remoEPSS 1.5%CVE-2022-34708MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.5%CVE-2026-13153HIGHEssential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products EndpointEPSS 1.5%CVE-2022-34710MEDIUMWindows Defender Credential Guard Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-34712MEDIUMWindows Defender Credential Guard Information Disclosure VulnerabilityEPSS 1.5%CVE-2021-3714—A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via EPSS 1.5%CVE-2018-16849LOWA flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presenceEPSS 1.5%CVE-2019-1010299—The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of unEPSS 1.5%CVE-2018-12126MEDIUMMicroarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an auEPSS 1.5%