Falhas do tipo CWE-200

4.917 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-22577CRITICALWhite Rabbit Switch - Password Disclosure VulnerabilityEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2021-21596CRITICALDell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remEPSS 0.8%CVE-2024-33309HIGHAn issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information viEPSS 0.8%CVE-2023-5576HIGHMigration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret ExposureEPSS 0.7%CVE-2025-27675CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Vulnerable OpenID Implementation V-EPSS 0.7%CVE-2013-10030MEDIUMExit Box Lite Plugin wordpress-exit-box-lite.php information disclosureEPSS 0.7%CVE-2023-27478MEDIUMDisclosure of unrelated data in libmemcached-awesome EPSS 0.7%CVE-2022-39307MEDIUMGrafana subject to Exposure of Sensitive Information resulting in User enumeration via forget passwordEPSS 0.7%CVE-2024-23302HIGHCouchbase Server before 7.2.4 has a private key leak in goxdcr.log.EPSS 0.7%CVE-2023-40049MEDIUMWS_FTP Server Information Disclosure via Directory ListingEPSS 0.7%CVE-2020-12518MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.EPSS 0.7%CVE-2023-49981HIGHA directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the EPSS 0.7%CVE-2023-20055HIGHCisco DNA Center Privilege Escalation VulnerabilityEPSS 0.7%CVE-2023-32082LOWetcd key name can be accessed via LeaseTimeToLive APIEPSS 0.7%CVE-2026-2861MEDIUMFoswiki Changes/Viewfile/Oops information disclosureEPSS 0.7%CVE-2025-45620HIGHAn issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted requestEPSS 0.7%CVE-2022-31177LOWPossible to infer sensitive information through query strings in Flask-AppBuilderEPSS 0.7%CVE-2021-20250—A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on theEPSS 0.7%CVE-2022-45103MEDIUM Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerabiEPSS 0.7%