Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-47633HIGHMicrosoft Cost Management Information Disclosure VulnerabilityEPSS 1.0%CVE-2024-21501MEDIUMVersions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attriEPSS 1.0%CVE-2023-26054MEDIUMCredentials inlined to Git URLs could end up in provenance attestation in BuildKitEPSS 1.0%CVE-2019-18334—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.0%CVE-2019-18333—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.0%CVE-2019-18335—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.0%CVE-2019-18331—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.0%CVE-2022-29235MEDIUMLimited data exposure for shared external videos in BigBlueButtonEPSS 1.0%CVE-2026-45793HIGHComposer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logsEPSS 1.0%CVE-2021-21301LOWVideo feed was captured while user has disabled videoEPSS 1.0%CVE-2022-46163HIGHtravel-support-program vulnerable to data exfiltration via Ransack query injectionEPSS 1.0%CVE-2021-39192MEDIUMPrivilege escalation: all users can access Admin-level API keysEPSS 1.0%CVE-2019-14839—It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password whenEPSS 1.0%CVE-2020-15235MEDIUMSensitive data exposure in RACTFEPSS 1.0%CVE-2019-15578—An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The patEPSS 1.0%CVE-2023-42505MEDIUMApache Superset: Sensitive information disclosure on db connection detailsEPSS 1.0%CVE-2022-32984HIGHBTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sEPSS 1.0%CVE-2017-7510—In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.EPSS 1.0%CVE-2023-32271MEDIUMAn information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS PlatEPSS 1.0%CVE-2021-35527HIGHPassword Autocomplete Vulnerability in Hitachi ABB Power Grids eSOMS ApplicationEPSS 1.0%