Falhas do tipo CWE-200

4.915 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-2106MEDIUMMasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST routeEPSS 0.8%CVE-2022-2704MEDIUMSourceCodester Simple E-Learning System downloadFiles.php information disclosureEPSS 0.8%CVE-2022-23643MEDIUMSide-channel attack in Sourcegraph Code MonitorsEPSS 0.8%CVE-2025-34272MEDIUMNagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard FallbackEPSS 0.8%CVE-2023-40058MEDIUMSensitive Information Disclosure Vulnerability EPSS 0.8%CVE-2017-3892LOWIn BlackBerry QNX Software Development Platform (SDP) 6.6.0, an information disclosure vulnerability in the default configuration of the QNXEPSS 0.8%CVE-2026-78386HIGHUnauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook APIEPSS 0.8%CVE-2021-22740—Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be expoEPSS 0.8%CVE-2023-48225HIGHLaf env causes sensitive information disclosureEPSS 0.8%CVE-2023-33848MEDIUMIBM CICS TX information disclosureEPSS 0.8%CVE-2023-6777MEDIUMWP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of ServiceEPSS 0.8%CVE-2023-5166HIGHDocker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URLEPSS 0.8%CVE-2021-20993MEDIUMWAGO: Managed Switches: Exposure of sensitive information through directory listingEPSS 0.8%CVE-2022-32739LOWOTRS version number is always in the exported ICS filesEPSS 0.8%CVE-2022-41971MEDIUMNextcloud Talk guests can continue to receive video streams from call after being removed from a conversationEPSS 0.8%CVE-2023-22503MEDIUMAffected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labelEPSS 0.8%CVE-2023-24827MEDIUMCredential disclosure in syft when SYFT_ATTEST_PASSWORD environment variable set in syftEPSS 0.8%CVE-2021-4180—An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attackeEPSS 0.8%CVE-2022-28607HIGHAn issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to gain sensitive infEPSS 0.8%CVE-2024-4596LOWKimai Session information disclosureEPSS 0.8%