Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2022-43959MEDIUMInsufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to EPSS 1.0%CVE-2022-35715MEDIUMIBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error messageEPSS 1.0%CVE-2025-10093MEDIUMD-Link DIR-852 Device Configuration getcfg.php phpcgi_main information disclosureEPSS 1.0%CVE-2010-1432—Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may EPSS 1.0%CVE-2022-20648MEDIUMCisco Redundancy Configuration Manager Debug Information Disclosure VulnerabilityEPSS 1.0%CVE-2026-25185MEDIUMWindows Shell Link Processing Spoofing VulnerabilityEPSS 1.0%CVE-2023-29517HIGHExposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewerEPSS 1.0%CVE-2023-47668MEDIUMWordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data ExposureEPSS 1.0%CVE-2018-15432—Cisco Prime Infrastructure Information Disclosure VulnerabilityEPSS 1.0%CVE-2018-15433—Cisco Prime Infrastructure Information Disclosure VulnerabilityEPSS 1.0%CVE-2024-5483MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON APIEPSS 1.0%CVE-2019-11268MEDIUMUAA SQL Identity Zone VulnerabilityEPSS 1.0%CVE-2022-0384—Video Conferencing with Zoom < 3.8.17 - E-mail Address DisclosureEPSS 1.0%CVE-2022-23469LOWAuthorization header displayed in the debug logsEPSS 1.0%CVE-2025-9196MEDIUMTrinity Audio <= 5.21.0 - Unauthenticated Information ExposureEPSS 1.0%CVE-2019-3868LOWKeycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIEPSS 1.0%CVE-2020-1779MEDIUMDynamic templates reveal sensitive data when OTRS tags are usedEPSS 1.0%CVE-2025-64670MEDIUMWindows DirectX Information Disclosure VulnerabilityEPSS 1.0%CVE-2020-36319LOWPotential sensitive data exposure in applications using Vaadin 15EPSS 1.0%CVE-2021-32689HIGHNextcloud Talk not properly disassociating users from chats after account deletionEPSS 1.0%