Falhas do tipo CWE-200

4.992 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-3780HIGHInformation exposure vulnerability on Technicolor CGA2121EPSS 0.2%CVE-2025-31256MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a usEPSS 0.2%CVE-2025-65104HIGHFirebird: Information leak vulnerability in firebird3 client when used with newer serverEPSS 0.2%CVE-2025-20030LOWExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.2%CVE-2026-22051LOWStorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerabiliEPSS 0.2%CVE-2025-11998MEDIUMHP Card Readers (B Models) – Potential Information DisclosureEPSS 0.2%CVE-2022-42442LOWIBM Robotic Process Automation for Cloud Pak information disclosureEPSS 0.2%CVE-2026-49988MEDIUMRepomix: attach_packed_output can bypass file-read secret scanning for supported local filesEPSS 0.2%CVE-2024-29720MEDIUMAn issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt componentEPSS 0.2%CVE-2025-31231MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitEPSS 0.2%CVE-2022-20591MEDIUMIn ppmpu_set of ppmpu.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information dEPSS 0.2%CVE-2024-2371MEDIUMInformation exposure vulnerability in Korenix JetI/O 6550EPSS 0.2%CVE-2024-45450MEDIUMPermission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.2%CVE-2023-38300MEDIUMA certain software build for the Orbic Maui device (Orbic/RC545L/RC545L:10/ORB545L_V1.4.2_BVZPP/230106:user/release-keys) leaks the IMEI andEPSS 0.2%CVE-2026-47395MEDIUMPraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model contextEPSS 0.2%CVE-2026-16592LOWWP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via ShortcodesEPSS 0.2%CVE-2022-46646LOWExposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enaEPSS 0.2%CVE-2025-57839MEDIUMPhoto module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentialityEPSS 0.2%CVE-2025-57838MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confideEPSS 0.2%CVE-2022-31221LOWDell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vuEPSS 0.2%