Falhas do tipo CWE-201

411 resultados

Exposição de informações sensíveis em dados enviados

A aplicação inclui dados sensíveis (senhas, tokens, chaves API, PII) em comunicações que não deveriam conter essa informação — logs, requisições HTTP não criptografadas, emails, respostas de erro, ou cache. O atacante consegue interceptar ou acessar esses dados sem autorização.

Exemplo

Um sistema de e-commerce que envia a senha do usuário em texto plano no email de confirmação de cadastro, ou uma API que registra tokens de autenticação em logs acessíveis. Outro caso comum: formulário enviado via HTTP (não HTTPS) contendo dados de cartão de crédito.

Como mitigar

Nunca inclua dados sensíveis em logs, mensagens de erro ou comunicações não criptografadas. Use HTTPS obrigatoriamente, implemente tratamento de exceções que não expõe detalhes, e revise sistematicamente o que é transmitido em cada canal (emails, APIs, respostas). Ferramentas de análise estática ajudam a detectar vazamentos de credenciais no código.

CVE-2022-28224MEDIUMCalico and Calico Enterprise may be vulnerable to route hijacking with the floating IP featureEPSS 0.6%CVE-2023-4002MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%CVE-2023-1975HIGHInsertion of Sensitive Information Into Sent Data in answerdev/answerEPSS 0.6%CVE-2024-53804HIGHWordPress WP Mailster plugin <= 1.8.16.0 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-34556MEDIUMWordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.5.4 - Sensitive Data Exposure via Exported File vulnerabilityEPSS 0.6%CVE-2024-34812MEDIUMWordPress ShopBuilder plugin <= 2.1.8 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2026-39912CRITICALv2board / Xboard Authentication Token Exposure via loginWithMailLinkEPSS 0.6%CVE-2023-3102MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%CVE-2024-35189MEDIUMSensitive Data Disclosure Vulnerability in Connection Configuration Endpoints in FidesEPSS 0.6%CVE-2022-23488MEDIUMBigBlueButton vulnerable to Insertion of Sensitive Information Into Sent DataEPSS 0.6%CVE-2023-6916HIGHInformation disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1EPSS 0.6%CVE-2025-59509MEDIUMWindows Speech Recognition Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-2620MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2024-25148MEDIUMIn Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, anEPSS 0.5%CVE-2024-56300HIGHWordPress Post/Page Copying Tool plugin <= 2.0.0 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-46665LOWAn insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in EPSS 0.5%CVE-2026-82209HIGHdomain-scoped PSL domain cookieEPSS 0.5%CVE-2023-1825LOWInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2021-1425MEDIUMCisco Cisco Email Security Appliance and Content Security Management Appliance Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-28173MEDIUMIn JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosedEPSS 0.5%