Falhas do tipo CWE-200

4.919 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-7328MEDIUMYouDianCMS information disclosureEPSS 0.7%CVE-2021-23193HIGHImproper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators EPSS 0.7%CVE-2021-36091LOWUnautorized access to the calendar appointmentsEPSS 0.7%CVE-2021-23204HIGHExposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be eEPSS 0.7%CVE-2024-35230MEDIUMWelcome and About GeoServer pages communicate version and revision informationEPSS 0.7%CVE-2019-3811MEDIUMA vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead oEPSS 0.7%CVE-2026-65017MEDIUMApache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)EPSS 0.7%CVE-2025-15082MEDIUMTOZED ZLT M30s Web Management proc_post information disclosureEPSS 0.7%CVE-2024-23662MEDIUMAn exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 thEPSS 0.7%CVE-2023-48294MEDIUMBroken Access control on Graphs Feature in LibreNMSEPSS 0.7%CVE-2023-6105MEDIUMManageEngine Information Disclosure in Multiple ProductsEPSS 0.7%CVE-2025-53066HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). EPSS 0.7%CVE-2022-47410CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2022-47411CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2021-39089MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.7%CVE-2018-3826—In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameEPSS 0.7%CVE-2024-29898MEDIUMOversight in fix for GHSA-4rcf-3cj2-46mq may have exposed suppressed wiki requests on private wikisEPSS 0.7%CVE-2026-26014MEDIUMPion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authentication keyEPSS 0.7%CVE-2025-34220MEDIUMVasion Print (formerly PrinterLogic) Unauthenticated API Leaks Group InformationEPSS 0.7%CVE-2026-20932MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 0.7%