Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2021-34576MEDIUMObservable discrepancy in Kaden PICOFLUX AiR leaks water consumptionEPSS 0.4%CVE-2026-26185MEDIUMDirectus Affected by User Enumeration via Password Reset Timing AttackEPSS 0.4%CVE-2026-79016MEDIUMObservable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTEPSS 0.4%CVE-2026-56327MEDIUMCapgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPCEPSS 0.4%CVE-2022-50800MEDIUMH3C SSL VPN n/a Username Enumeration via Login Script Credential VerificationEPSS 0.4%CVE-2026-56296MEDIUMCap-go - App Existence Oracle via Unauthenticated transfer_app RPCEPSS 0.4%CVE-2026-55555LOWDompdf: File existence oracle via font-face stylesheet declarationEPSS 0.4%CVE-2023-46739MEDIUMTiming attack can leak user passwordsEPSS 0.4%CVE-2023-53943MEDIUMGLPI 9.5.7 Username Enumeration Vulnerability via Lost Password EndpointEPSS 0.4%CVE-2026-87478MEDIUMObservable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a cEPSS 0.4%CVE-2024-1544MEDIUMECDSA nonce bias caused by truncationEPSS 0.3%CVE-2026-26895MEDIUMUser enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the plEPSS 0.3%CVE-2023-32694MEDIUMNon-constant time HMAC comparison in Adyen plugin in SaleorEPSS 0.3%CVE-2024-41880MEDIUMIn veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and pEPSS 0.3%CVE-2025-6011LOWTiming Side-Channel in Vault’s Userpass Auth MethodEPSS 0.3%CVE-2025-52576MEDIUMKanboard vulnerable to Username Enumeration via Login Behavior and Bruteforce Protection BypassEPSS 0.3%CVE-2024-45678MEDIUMYubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extracEPSS 0.3%CVE-2025-64749MEDIUMDirectus Vulnerable to Information Leakage in Existing CollectionsEPSS 0.3%CVE-2025-0361MEDIUMDuring an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration frEPSS 0.3%CVE-2026-79030MEDIUMObservable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a cEPSS 0.3%