Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2025-46720LOWKeystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fieldsEPSS 0.3%CVE-2025-23182MEDIUMUBtech – CWE-203: Observable DiscrepancyEPSS 0.3%CVE-2026-3579LOWNon-constant time multiplication subroutine __muldi3 on RISC-V RV32IEPSS 0.3%CVE-2026-14112MEDIUMInappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage EPSS 0.3%CVE-2026-37064MEDIUMUser enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the appEPSS 0.3%CVE-2025-39665MEDIUMLivestatus Injection in dynmapsEPSS 0.3%CVE-2026-87518MEDIUMObservable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the rEPSS 0.3%CVE-2026-74954HIGHInformation disclosure due to side-channel in the Storage: Cache API componentEPSS 0.3%CVE-2025-11932LOWTiming Side-Channel in PSK Binder VerificationEPSS 0.3%CVE-2024-41760LOWIBM Common Cryptographic Architecture information disclosureEPSS 0.3%CVE-2026-23621MEDIUMGFI MailEssentials AI < 22.4 ListServer.IsPathExist() Absolute Directory Traversal to File EnumerationEPSS 0.3%CVE-2026-72632HIGHObservable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API KeysEPSS 0.3%CVE-2026-74961CRITICALSide-channel in the Web Audio componentEPSS 0.3%CVE-2025-5802MEDIUMUsername Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account DiscoveryEPSS 0.3%CVE-2025-1396LOWUsername Enumeration in Multiple WSO2 Products with Multi-Attribute Login EnabledEPSS 0.3%CVE-2024-38465MEDIUMShenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus erroEPSS 0.3%CVE-2021-33149MEDIUMObservable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via EPSS 0.2%CVE-2026-87459MEDIUMObservable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a craEPSS 0.2%CVE-2025-24506MEDIUMA specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.EPSS 0.2%CVE-2022-46724LOWThis issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.4 and iPadOS 16.4. A person with pEPSS 0.2%