Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-40151MEDIUMPraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOSEPSS 0.8%CVE-2022-39289CRITICALDatabase log access in ZoneMinderEPSS 0.8%CVE-2022-32741MEDIUMInformation disclosure in Request New Password featureEPSS 0.8%CVE-2024-47197HIGHMaven Archetype Plugin: Maven Archetype integration-test may package local settings into the published artifact, possibly containing credentialsEPSS 0.8%CVE-2022-32229MEDIUMA information disclosure vulnerability exists in Rockert.Chat <v5 due to /api/v1/chat.getThreadsList lack of sanitization of user inputs andEPSS 0.8%CVE-2022-32228MEDIUMAn information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 since the getReadReceipts Meteor server method does nEPSS 0.8%CVE-2026-54649LOWpunchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-ToEPSS 0.8%CVE-2021-43823MEDIUMSide-channel attack in SourcegraphEPSS 0.8%CVE-2023-39951MEDIUMInstrumentation for AWS SDK v2 captures email content when using Amazon Simple Email Service (SES) v1 API, exposing that content to the telemetry backendEPSS 0.8%CVE-2024-41700HIGHBarix – CWE-200 Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.8%CVE-2020-12496MEDIUMENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 2.x exposures sensitive information to an unauthorized actorEPSS 0.8%CVE-2023-4061MEDIUMWildfly-core: management user rbac permission allows unexpected reading of system-properties to an unauthorized actorEPSS 0.8%CVE-2021-31352MEDIUMSRC Series: NETCONF over SSH allows negotiation of weak ciphersEPSS 0.8%CVE-2025-24146CRITICALThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, mEPSS 0.8%CVE-2020-10618—LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.EPSS 0.8%CVE-2022-35296—Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive iEPSS 0.8%CVE-2025-14726MEDIUMWidgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpointsEPSS 0.8%CVE-2024-4300CRITICALE-WEBInformationCo. FS-EZViewer(Web) - Sensitive Data ExposureEPSS 0.8%CVE-2026-90881MEDIUMD-Link DIR-882 CGI Binary dllog.cgi main information disclosureEPSS 0.8%CVE-2026-1980MEDIUMWPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data ExposureEPSS 0.8%