Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-3689LOWZhejiang Land Zongheng Network Technology O2OA information disclosureEPSS 0.9%CVE-2025-56427HIGHDirectory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_EPSS 0.9%CVE-2024-1139HIGHCluster-monitoring-operator: credentials leakEPSS 0.9%CVE-2021-41123MEDIUMExposure of Sensitive Information to an Unauthorized Actor in WB.UI.Headquarters.dllEPSS 0.9%CVE-2021-32695LOWMalicious Android app could access Shared Preferences of the Nextcloud Android clientEPSS 0.9%CVE-2021-32720MEDIUMList of order ids, number, items total and token value exposed for unauthorized uses via new APIEPSS 0.9%CVE-2022-24849MEDIUMContact to DisCatSharp-owned server using authenticated clientEPSS 0.9%CVE-2021-3566—Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file tEPSS 0.9%CVE-2022-40177—A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 0.9%CVE-2021-27424MEDIUMGE UR family exposure of sensitive information to an unauthorized actorEPSS 0.9%CVE-2022-23497MEDIUMInsecure file access in FreshRSSEPSS 0.9%CVE-2021-39224LOWFile path disclosure of shared files in OfficeOnline applicationEPSS 0.9%CVE-2022-41707MEDIUMRelatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user of the application. TEPSS 0.9%CVE-2020-3547MEDIUMCisco Email Security Appliance, Cisco Content Security Management Appliance, and Cisco Web Security Appliance Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-87820MEDIUMCyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI ScannerEPSS 0.9%CVE-2026-47282MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.9%CVE-2021-1562MEDIUMCisco BroadWorks Application Server Information Disclosure VulnerabilityEPSS 0.9%CVE-2021-34702MEDIUMCisco Identity Services Engine Sensitive Information Disclosure VulnerabilityEPSS 0.9%CVE-2024-11961MEDIUMGuangzhou Huayi Intelligent Technology Jeewms WmOmNoticeHController.java preHandle information disclosureEPSS 0.9%CVE-2025-30474MEDIUMApache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error messageEPSS 0.9%