Falhas do tipo CWE-201

411 resultados

Exposição de informações sensíveis em dados enviados

A aplicação inclui dados sensíveis (senhas, tokens, chaves API, PII) em comunicações que não deveriam conter essa informação — logs, requisições HTTP não criptografadas, emails, respostas de erro, ou cache. O atacante consegue interceptar ou acessar esses dados sem autorização.

Exemplo

Um sistema de e-commerce que envia a senha do usuário em texto plano no email de confirmação de cadastro, ou uma API que registra tokens de autenticação em logs acessíveis. Outro caso comum: formulário enviado via HTTP (não HTTPS) contendo dados de cartão de crédito.

Como mitigar

Nunca inclua dados sensíveis em logs, mensagens de erro ou comunicações não criptografadas. Use HTTPS obrigatoriamente, implemente tratamento de exceções que não expõe detalhes, e revise sistematicamente o que é transmitido em cada canal (emails, APIs, respostas). Ferramentas de análise estática ajudam a detectar vazamentos de credenciais no código.

CVE-2025-47541HIGHWordPress Mail Mint plugin <= 1.17.7 - Sensitive Data Exposure VulnerabilityEPSS 0.5%CVE-2023-3399HIGHInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-31134MEDIUMFreshRSS vulnerable to directory enumeration via ext.phpEPSS 0.4%CVE-2024-49235HIGHWordPress Contact Forms, Live Support, CRM, Video Messages plugin <= 1.10.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-49584HIGHXWiki makes title of inaccessible pages available through the class property values REST APIEPSS 0.4%CVE-2026-41181MEDIUMTraefik: Errors middleware forwards Authorization and Cookie headers to separate error page serviceEPSS 0.4%CVE-2024-26270MEDIUMThe Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 EPSS 0.4%CVE-2025-22303MEDIUMWordPress WP Mailster plugin <= 1.8.17.0 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-25150MEDIUMInformation disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and LiferayEPSS 0.4%CVE-2026-13437MEDIUMInsertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticatEPSS 0.4%CVE-2026-42997HIGHAn issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be senEPSS 0.4%CVE-2025-48749CRITICALNetwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent DaEPSS 0.4%CVE-2026-54171MEDIUMExcon: redact additional sensitive/risky headers when following redirectsEPSS 0.4%CVE-2025-48934MEDIUMDeno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesEPSS 0.4%CVE-2024-38787HIGHWordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerabilityEPSS 0.4%CVE-2026-6267HIGHInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.4%CVE-2025-64502MEDIUMParse Server allows public `explain` queries which may expose sensitive database performance information and schema detailsEPSS 0.4%CVE-2024-39315MEDIUMPomerium exposed OAuth2 access and ID tokens in user info endpoint responseEPSS 0.4%CVE-2026-7189HIGHSensitive Data Exposure in Proliz's OBSEPSS 0.4%CVE-2026-54834HIGHWordPress Object Cache 4 everyone plugin <= 2.3.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%