Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-53694HIGHInformation Disclosure in ItemServices APIEPSS 6.0%CVE-2021-24227—Patreon WordPress < 1.7.0 - Unauthenticated Local File DisclosureEPSS 5.9%CVE-2019-13511—Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted AEPSS 5.8%CVE-2021-25118—Yoast SEO 16.7-17.2 - Unauthenticated Full Path DisclosureEPSS 5.6%CVE-2019-14892HIGHA flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserializationEPSS 5.6%CVE-2022-30184MEDIUM.NET and Visual Studio Information Disclosure VulnerabilityEPSS 5.6%CVE-2018-15962MEDIUMAdobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerEPSS 5.5%CVE-2025-55190CRITICALArgo CD: Project API Token Exposes Repository CredentialsEPSS 5.5%CVE-2023-4714MEDIUMPlayTube Redirect information disclosureEPSS 5.5%CVE-2021-35936—No Authentication on Logging ServerEPSS 5.5%CVE-2023-42820HIGHRandom seed leakage in JumpserverEPSS 5.4%CVE-2021-24226—AccessAlly < 3.5.7 - $_SERVER Superglobal LeakageEPSS 5.4%CVE-2022-1815MEDIUMExposure of Sensitive Information to an Unauthorized Actor in jgraph/drawioEPSS 5.4%CVE-2024-1208MEDIUMLearnDash LMS <= 4.10.2 - Sensitive Information Exposure via APIEPSS 5.3%CVE-2021-3773—A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditionalEPSS 5.3%CVE-2018-10915HIGHA vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between coEPSS 5.2%CVE-2022-30556—Information Disclosure in mod_lua with websocketsEPSS 5.1%CVE-2022-29901MEDIUMArbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed)EPSS 5.0%CVE-2021-22925MEDIUMcurl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=conEPSS 4.9%CVE-2022-28614—read beyond bounds via ap_rwrite()EPSS 4.9%