Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2024-51477MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.3%CVE-2026-25562MEDIUMWeKan < 8.19 Attachments Publication Information DisclosureEPSS 0.3%CVE-2023-30312HIGHAn issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to EPSS 0.3%CVE-2026-14071MEDIUMSide-channel information leakage in WebAudio in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data viaEPSS 0.3%CVE-2024-47869LOWNon-constant-time comparison when comparing hashes in GradioEPSS 0.3%CVE-2026-8242MEDIUMIndustrial Application Software IAS Canias ERP Login RMI doAction response discrepancyEPSS 0.3%CVE-2026-4045MEDIUMprojectsend Auth.php response discrepancyEPSS 0.3%CVE-2024-45089MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.3%CVE-2026-44263MEDIUMWeblate: Private Translation Enumeration via Screenshot APIEPSS 0.3%CVE-2025-12888LOWConstant Time Issue with Xtensa-based ESP32 and X22519EPSS 0.3%CVE-2025-43743MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2025-43739MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2026-67193MEDIUMXlight FTP Server < 3.9.5 Information Disclosure via USER CommandEPSS 0.3%CVE-2024-55374MEDIUMREDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.EPSS 0.3%CVE-2026-23931MEDIUMFrontend plaintext macro value enumeration via the validatate.api.exists actionEPSS 0.3%CVE-2022-48220MEDIUMPotential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusioEPSS 0.3%CVE-2026-79287MEDIUMObservable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafEPSS 0.3%CVE-2026-79242MEDIUMObservable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a craftEPSS 0.3%CVE-2025-54477MEDIUMJoomla! Core - [20250902] User-Enumeration in passkey authentication methodEPSS 0.3%CVE-2024-54476MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app mEPSS 0.3%