Falhas do tipo CWE-200

4.793 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2022-23952HIGHIn Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.EPSS 1.4%CVE-2021-32690MEDIUMRepository credentials passed to alternate domainEPSS 1.4%CVE-2022-0812—An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker EPSS 1.4%CVE-2022-40629HIGHSensitive Information Disclosure Vulnerability in Tacitine FirewallEPSS 1.4%CVE-2021-31567MEDIUMWordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerabilityEPSS 1.4%CVE-2022-41876HIGHezplatform-graphql GraphQL queries can expose password hashesEPSS 1.4%CVE-2022-27241—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (AllEPSS 1.4%CVE-2019-15583—An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When anEPSS 1.4%CVE-2021-32747MEDIUMCustom variable protection and blacklists can be circumventedEPSS 1.4%CVE-2023-40510HIGHLG Simple Editor getServerSetting Authentication Bypass VulnerabilityEPSS 1.4%CVE-2023-40511HIGHLG Simple Editor checkServer Authentication Bypass VulnerabilityEPSS 1.4%CVE-2022-21712HIGHCookie and header exposure in twistedEPSS 1.4%CVE-2021-37629MEDIUMLack of ratelimit on Richdocuments OCS endpoint in nextcloudEPSS 1.4%CVE-2026-2025HIGHMail Mint < 1.19.5 - Unauthenticated Emails DisclosureEPSS 1.4%CVE-2019-6852HIGHA CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium coEPSS 1.4%CVE-2020-7510—A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtainEPSS 1.4%CVE-2022-24797MEDIUMExposure of Sensitive Information in PomeriumEPSS 1.4%CVE-2024-42658HIGHAn issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's paraEPSS 1.4%CVE-2020-11009MEDIUMIDOR can reveal execution data and logs to unauthorized user in RundeckEPSS 1.4%CVE-2021-22905—Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being perforEPSS 1.4%