Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-46437MEDIUMA sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote aEPSS 1.2%CVE-2023-48796—Apache dolphinscheduler sensitive information disclosureEPSS 1.2%CVE-2025-53781HIGHAzure Virtual Machines Information Disclosure VulnerabilityEPSS 1.2%CVE-2026-55450CRITICALLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leakEPSS 1.2%CVE-2025-30426CRITICALThis issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 1EPSS 1.2%CVE-2025-31183CRITICALThe issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 1EPSS 1.2%CVE-2018-13291MEDIUMInformation exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenEPSS 1.2%CVE-2021-29086MEDIUMExposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.EPSS 1.2%CVE-2026-49336MEDIUM@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapterEPSS 1.2%CVE-2018-13281MEDIUMInformation exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated useEPSS 1.2%CVE-2017-16225—aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm tEPSS 1.2%CVE-2021-24585—Timetable and Event Schedule by MotoPress < 2.4.0 - Arbitrary User's Hashed Password/Email/Username DisclosureEPSS 1.2%CVE-2026-27796MEDIUMHomarr: Unauthenticated Information Disclosure (Integration Metadata Leak)EPSS 1.2%CVE-2022-21677MEDIUMGroup advanced search option may leak group and group's members visibility EPSS 1.2%CVE-2026-42826CRITICALAzure DevOps Information Disclosure VulnerabilityEPSS 1.2%CVE-2022-1774HIGHExposure of Sensitive Information to an Unauthorized Actor in jgraph/drawioEPSS 1.2%CVE-2022-1186MEDIUMBe POPIA Compliant <= 1.1.5 - Sensitive Information ExposureEPSS 1.2%CVE-2022-0722MEDIUMExposure of Sensitive Information to an Unauthorized Actor in ionicabizau/parse-urlEPSS 1.2%CVE-2024-6633CRITICALInsecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)EPSS 1.2%CVE-2018-11727MEDIUMThe libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an EPSS 1.2%