Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-42878MEDIUMFacturaScripts: Unauthenticated phpinfo() Disclosure via Installer Endpoint in FacturaScriptsEPSS 0.9%CVE-2021-25110—Futurio Extra < 1.6.3 - Subscriber+ User Email Address DisclosureEPSS 0.9%CVE-2021-33709—A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versionEPSS 0.9%CVE-2023-43796MEDIUMSynapse vulnerable to leak of remote user device informationEPSS 0.9%CVE-2021-39163LOWAdding a private/unlisted room to a community exposes room metadata in an unauthorised manner.EPSS 0.9%CVE-2017-15138MEDIUMThe OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidentiaEPSS 0.9%CVE-2022-31190MEDIUMMetadata of withdrawn Items is exposed to anonymous users in DSpace XMLUIEPSS 0.9%CVE-2023-26476HIGHTwo XWiki Platform UIs Expose Sensitive Information to an Unauthorized ActorEPSS 0.9%CVE-2026-21532HIGHAzure Function Information Disclosure VulnerabilityEPSS 0.9%CVE-2017-12310—A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sEPSS 0.9%CVE-2023-6101MEDIUMMaiwei Safety Production Control Platform Intelligent Monitoring ha.html information disclosureEPSS 0.9%CVE-2022-27633MEDIUMAn information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specEPSS 0.9%CVE-2022-31134MEDIUMZulip Server public data export contains attachments that are non-publicEPSS 0.9%CVE-2022-27630MEDIUMAn information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A spEPSS 0.9%CVE-2022-31162HIGHSlack Morphism for Rust before 0.41.0 can accidentally leak Slack OAuth client information in application debug logsEPSS 0.9%CVE-2024-23321HIGHApache RocketMQ: Unauthorized Exposure of Sensitive DataEPSS 0.9%CVE-2021-24164—Ninja Forms < 3.4.34.1 - Authenticated OAuth Connection Key DisclosureEPSS 0.9%CVE-2023-7094MEDIUMNetentsec NS-ASG Application Security Gateway nsasg6.0.tgz information disclosureEPSS 0.9%CVE-2025-59716MEDIUMownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insEPSS 0.9%CVE-2013-10007MEDIUMethitter WP-Print-Friendly wp-print-friendly.php information disclosureEPSS 0.9%