Falhas do tipo CWE-200

4.985 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-93383MEDIUMInformation leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTEPSS 0.3%CVE-2025-24280MEDIUMAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app mEPSS 0.3%CVE-2024-23236MEDIUMA correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary filesEPSS 0.3%CVE-2024-27884MEDIUMThis issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2EPSS 0.3%CVE-2026-48007HIGHElement Call reports full URLs of visited pages to analytics serverEPSS 0.3%CVE-2021-3585—A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-EPSS 0.3%CVE-2025-1868MEDIUMInformation display on multiple products from Famatech CorpEPSS 0.3%CVE-2026-71883HIGHNative AES packet cipher returns the raw AES key on an aliasEPSS 0.3%CVE-2025-47288LOWDiscourse Policy plugin private group members visibleEPSS 0.3%CVE-2025-15141LOWHalo Configuration actuator information disclosureEPSS 0.3%CVE-2024-23292LOWThis issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be abEPSS 0.3%CVE-2026-2832MEDIUMCertain Samsung MultiXpress Multifunction Printers Firmware – Potential Information DisclosureEPSS 0.3%CVE-2026-47132MEDIUMphpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User EnumerationEPSS 0.3%CVE-2023-28826MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS MonterEPSS 0.3%CVE-2022-45454LOWSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before buiEPSS 0.3%CVE-2024-45054LOWPotential Permission Leakage of Cluster Level in hwameistorEPSS 0.3%CVE-2026-19782MEDIUMWPS Bidouille < 1.33.5 - Subscriber+ User Email Disclosure via wps_get_usersEPSS 0.3%CVE-2026-14567MEDIUMWP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User DirectoryEPSS 0.3%CVE-2026-83419MEDIUMVulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPEPSS 0.3%CVE-2023-29114MEDIUMUnauthorized System Log Disclosure in Enel X JuiceBoxEPSS 0.3%