Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-45811MEDIUMserver.fs.deny bypassed when using ?import&raw in viteEPSS 1.1%CVE-2021-34707MEDIUMCisco Evolved Programmable Network Manager Sensitive Information Disclosure VulnerabilityEPSS 1.1%CVE-2023-34235HIGHLeaking sensitive user information still possible by filtering on private with prefix fieldsEPSS 1.1%CVE-2025-34098HIGHRiverbed SteelHead VCX Authenticated Arbitrary File Read via Log Filter InjectionEPSS 1.1%CVE-2021-21396MEDIUMBulk list client endpoint exposes too much metadata about a clientEPSS 1.1%CVE-2021-3503—A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerabilityEPSS 1.1%CVE-2019-12708MEDIUMCisco SPA100 Series Analog Telephone Adapters Administrative Credentials Information Disclosure VulnerabilityEPSS 1.1%CVE-2021-44141—All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory existsEPSS 1.1%CVE-2019-15257MEDIUMCisco SPA100 Series Analog Telephone Adapters Running Configuration Information Disclosure VulnerabilityEPSS 1.1%CVE-2025-4752MEDIUMD-Link DI-7003GV2 install_base.data information disclosureEPSS 1.1%CVE-2025-4750MEDIUMD-Link DI-7003GV2 Configuration get_version.data information disclosureEPSS 1.1%CVE-2025-4753MEDIUMD-Link DI-7003GV2 login.data information disclosureEPSS 1.1%CVE-2022-23607MEDIUMUnsafe handling of user-specified cookies in treqEPSS 1.1%CVE-2023-23839MEDIUMSolarWinds Platform Exposure of Sensitive Information VulnerabilityEPSS 1.1%CVE-2019-10209LOWPostgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.EPSS 1.1%CVE-2020-3242MEDIUMCisco UCS Director Information Disclosure VulnerabilityEPSS 1.1%CVE-2021-36198HIGHEntrapassEPSS 1.1%CVE-2021-32528MEDIUMQSAN Storage Manager - Exposure of Sensitive Information to an Unauthorized ActorEPSS 1.1%CVE-2021-22728—A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink ParkingEPSS 1.1%CVE-2022-48258MEDIUMIn Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.EPSS 1.1%