Falhas do tipo CWE-200

4.909 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2018-12126MEDIUMMicroarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an auEPSS 1.5%CVE-2025-24011MEDIUMUmbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response CodesEPSS 1.5%CVE-2021-32029—A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read EPSS 1.5%CVE-2024-10916MEDIUMD-Link DNS-320/DNS-320LW/DNS-325/DNS-340L HTTP GET Request info.xml information disclosureEPSS 1.5%CVE-2023-1387MEDIUMGrafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to searcEPSS 1.5%CVE-2023-24881MEDIUMMicrosoft Teams Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-27844LOWWordPress WPvivid plugin <= 0.9.70 - Arbitrary File Read vulnerabilityEPSS 1.5%CVE-2008-3893MEDIUMMicrosoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear thisEPSS 1.5%CVE-2018-10852LOWThe UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone EPSS 1.5%CVE-2021-21336MEDIUMExposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManagerEPSS 1.5%CVE-2022-47184HIGHApache Traffic Server: The TRACE method can be use to disclose network informationEPSS 1.5%CVE-2023-33933HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.5%CVE-2018-0474MEDIUMCisco Unified Communications Manager Digest Credentials Disclosure VulnerabilityEPSS 1.5%CVE-2026-52815MEDIUMGogs: Unauthenticated Organization Teams Information Disclosure via APIEPSS 1.5%CVE-2018-13288MEDIUMInformation exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remoteEPSS 1.5%CVE-2018-13297MEDIUMInformation exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitEPSS 1.5%CVE-2018-0218—A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticateEPSS 1.5%CVE-2018-0207—A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticateEPSS 1.5%CVE-2017-11510—An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator usEPSS 1.5%CVE-2018-0187MEDIUMCisco Identity Services Engine Privileged Account Sensitive Information Disclosure VulnerabilityEPSS 1.5%