Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2026-79028MEDIUMObservable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crEPSS 0.3%CVE-2026-53933MEDIUMMaravel-Framework Vulnerable to Side-Channel Information Disclosure (Error Oracle) via Dynamic Route FuzzingEPSS 0.3%CVE-2026-78617MEDIUMWatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate LimitingEPSS 0.3%CVE-2025-11145HIGHUser Enumeration in CBK Soft's enVisionEPSS 0.3%CVE-2025-40732HIGHUser enumeration vulnerability in Daily Expense ManagerEPSS 0.3%CVE-2023-5872MEDIUMWago: Vulnerability in Smart Designer Web-ApplicationEPSS 0.3%CVE-2025-6056MEDIUMTiming difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackeEPSS 0.3%CVE-2026-33429MEDIUMParse Server: Protected field change detection oracle via LiveQuery watch parameterEPSS 0.3%CVE-2023-28200MEDIUMA validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, EPSS 0.3%CVE-2024-47057MEDIUMUser name enumeration possible due to response time difference on password reset formEPSS 0.3%CVE-2026-59341MEDIUMSealed Secrets: decryption oracle via Go template injection in unauthenticated controller endpointsEPSS 0.3%CVE-2026-23937MEDIUMHost PSK extraction in Zabbix APIEPSS 0.3%CVE-2025-47872MEDIUMEG4 Electronics EG4 Inverters Observable DiscrepancyEPSS 0.3%CVE-2025-56423MEDIUMAn issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitEPSS 0.3%CVE-2024-54002MEDIUMDependency-Track allows enumeration of managed users via /api/v1/user/login endpointEPSS 0.3%CVE-2025-59702HIGHEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.3%CVE-2025-10890CRITICALSide-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crEPSS 0.3%CVE-2025-43751MEDIUMUser enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 202EPSS 0.3%CVE-2026-56319MEDIUMCapgo - App Existence Oracle via GET /statistics/app/:app_idEPSS 0.3%CVE-2023-38327MEDIUMAn issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unautEPSS 0.3%