Falhas do tipo CWE-200

4.992 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-32670HIGHExposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes to potentially identEPSS 0.2%CVE-2022-39859MEDIUMImplicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive information via impEPSS 0.2%CVE-2024-22331MEDIUMIBM UrbanCode Deploy information disclosureEPSS 0.2%CVE-2023-1055—A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificaEPSS 0.2%CVE-2026-54605HIGHOAuth: Cross-origin token-request redirects can expose signed request metadataEPSS 0.2%CVE-2024-20914LOWVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected EPSS 0.2%CVE-2024-8097MEDIUMSensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST levelEPSS 0.2%CVE-2026-100640HIGHSiYuan before v3.8.4 Clipboard Data Disclosure via IPCEPSS 0.2%CVE-2022-34355MEDIUMIBM Jazz Foundation information disclosureEPSS 0.2%CVE-2025-43523MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may beEPSS 0.2%CVE-2026-16302MEDIUMSpectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.2%CVE-2024-54009MEDIUMRemote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited EPSS 0.2%CVE-2026-88013LOWrclone: http backend forwards custom/auth headers to a different host on redirectEPSS 0.2%CVE-2025-46283MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. AnEPSS 0.2%CVE-2026-82841MEDIUMUpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration NoticeEPSS 0.2%CVE-2022-32931MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to EPSS 0.2%CVE-2023-5920LOWLack Of Secure Keyboard Entry Protection in MacOS DesktopEPSS 0.2%CVE-2024-3780HIGHInformation exposure vulnerability on Technicolor CGA2121EPSS 0.2%CVE-2026-40159MEDIUMPraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess ExecutionEPSS 0.2%CVE-2025-65104HIGHFirebird: Information leak vulnerability in firebird3 client when used with newer serverEPSS 0.2%