Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-6248CRITICALData leakage and arbitrary remote code execution in Syrus cloud devicesEPSS 1.2%CVE-2018-0109—A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access sensitive data about the application.EPSS 1.2%CVE-2017-16741—An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0EPSS 1.2%CVE-2025-58751LOWVite middleware may serve files starting with the same name with the public directoryEPSS 1.2%CVE-2021-29483CRITICALwikiconfig API leaked private config variables set through ManageWikiEPSS 1.2%CVE-2020-25192MEDIUMMOXA NPort IAW5000A-I/O SeriesEPSS 1.2%CVE-2022-23982MEDIUMWordPress Perfect Brands for WooCommerce plugin <= 2.0.4 - Server Information Exposure vulnerabilityEPSS 1.2%CVE-2024-0716LOWByzoro Smart S150 Management Platform Backup File download.php information disclosureEPSS 1.2%CVE-2023-43804MEDIUM`Cookie` HTTP header isn't stripped on cross-origin redirectsEPSS 1.2%CVE-2024-29987MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.2%CVE-2017-6793—A vulnerability in the Inventory Management feature of Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attaEPSS 1.2%CVE-2023-0836HIGHAn information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.EPSS 1.2%CVE-2023-5070MEDIUMSocial Media Share Buttons & Social Sharing Icons <= 2.8.5 - Information ExposureEPSS 1.2%CVE-2022-46651—Apache Airflow: Security vulnerability on AirFlow ConnectionsEPSS 1.2%CVE-2021-25375MEDIUMUsing predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emaEPSS 1.2%CVE-2021-32731MEDIUMThe reset password form reveal users email addressEPSS 1.2%CVE-2024-8852MEDIUMAll-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error LogsEPSS 1.2%CVE-2019-1692MEDIUMCisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure VulnerabilityEPSS 1.2%CVE-2023-40029CRITICALCluster secret might leak in cluster details page in Argo CDEPSS 1.2%CVE-2019-7005MEDIUMUnauthenticated Information Disclosure Vulnerability in IP OfficeEPSS 1.2%