Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2021-32712MEDIUMInformation leakage in Error HandlerEPSS 1.1%CVE-2024-37325HIGHAzure Science Virtual Machine (DSVM) Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2019-5465—An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosEPSS 1.1%CVE-2021-41239MEDIUMUser enumeration setting not respected in Nextcloud serverEPSS 1.1%CVE-2020-3472MEDIUMCisco Webex Meetings User Email Address Information Disclosure VulnerabilityEPSS 1.1%CVE-2023-33165MEDIUMMicrosoft SharePoint Server Security Feature Bypass VulnerabilityEPSS 1.1%CVE-2022-23498HIGHWhen query caching is enabled in Grafana users can query another users sessionEPSS 1.1%CVE-2022-2117MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information DisclosureEPSS 1.1%CVE-2024-26144MEDIUMPossible Sensitive Session Information Leak in Active StorageEPSS 1.1%CVE-2022-23619MEDIUMInformation exposure in xwiki-platformEPSS 1.1%CVE-2017-20194MEDIUMFormidable Form Builder < 2.05.03 - Unauthenticated Information DisclosureEPSS 1.1%CVE-2022-24837MEDIUMEnumerable upload file names in hedgedocEPSS 1.1%CVE-2022-30598—A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise haEPSS 1.1%CVE-2021-41124HIGHSplash authentication credentials potentially leaked to target websites in scrapy-splashEPSS 1.1%CVE-2021-25369MEDIUMAn improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.EPSS 1.1%KEVCVE-2024-33575MEDIUMWordPress User Meta plugin <= 3.0 - Sensitive Data Exposure vulnerabilityEPSS 1.1%CVE-2024-26177MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.1%CVE-2020-11059CRITICALExposure of Sensitive Information to an Unauthorized Actor in AEgirEPSS 1.1%CVE-2017-20007MEDIUMInformation Exposure in INGEPAC DA AUEPSS 1.1%CVE-2023-34134—Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to reaEPSS 1.1%