Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-24408MEDIUMAdobe Commerce | Information Exposure (CWE-200)EPSS 1.0%CVE-2022-32220MEDIUMAn information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messageEPSS 1.0%CVE-2021-22721—A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink ParkingEPSS 1.0%CVE-2022-41939MEDIUMCredential exposure when running third-party builders in knative/funcEPSS 1.0%CVE-2022-29241HIGHKnown or guessable hidden files may be accessed in Jupyter ServerEPSS 0.9%CVE-2026-40379CRITICALAzure Entra ID Spoofing VulnerabilityEPSS 0.9%CVE-2017-6040—An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitivEPSS 0.9%CVE-2026-0717MEDIUMLottieFiles – Lottie block for Gutenberg <= 3.0.0 - Unauthenticated Sensitive Information ExposureEPSS 0.9%CVE-2021-36095MEDIUMUser enumeration issue using "lost password" featureEPSS 0.9%CVE-2022-31068MEDIUMSensitive Data Exposure on Refused Inventory Files in GLPIEPSS 0.9%CVE-2021-39203MEDIUMPrivate data disclosure/privilege escalation through the block editor in WordpressEPSS 0.9%CVE-2020-15080MEDIUMInformation disclosure in release archive in PrestaShopEPSS 0.9%CVE-2022-2907MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 beforeEPSS 0.9%CVE-2025-24253CRITICALThis issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 1EPSS 0.9%CVE-2021-42536HIGHEmerson WirelessHART GatewayEPSS 0.9%CVE-2024-21140MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: HotspotEPSS 0.9%CVE-2023-39620—An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via thEPSS 0.9%CVE-2024-34788MEDIUMAn improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially senEPSS 0.9%CVE-2019-15963MEDIUMCisco Unified Communications Manager Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-47855CRITICALAn exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3EPSS 0.9%