Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2026-79181MEDIUMObservable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a craftEPSS 0.2%CVE-2026-87566MEDIUMObservable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a craftEPSS 0.2%CVE-2026-59640HIGHOpenPGP CFB quick-check oracle active on symmetric/session-key pathsEPSS 0.2%CVE-2025-46804LOWScreen 5.0.0 and older versions allow file existence tests when installed setuid-rootEPSS 0.2%CVE-2025-13166LOWUsername Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account DiscoveryEPSS 0.2%CVE-2026-87539LOWObservable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafteEPSS 0.2%CVE-2018-9364HIGHIn the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure booEPSS 0.2%CVE-2026-45294MEDIUMFreeScout: User Account Enumeration via Password Reset Response DifferentiationEPSS 0.2%CVE-2024-23984MEDIUMObservable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosuEPSS 0.2%CVE-2026-33425MEDIUMDiscourse has inferable private group membership or existence via exclude_groups parameterEPSS 0.2%CVE-2024-27839MEDIUMA privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicioEPSS 0.2%CVE-2026-45410MEDIUMTime-based user enumeration in TREK authentication endpointEPSS 0.2%CVE-2026-73630MEDIUMSiYuan before v3.7.4 Information Disclosure via authFilePublishAccessEPSS 0.2%CVE-2026-72699CRITICALGrav Login Plugin before 3.9.1 Email Enumeration via RegistrationEPSS 0.2%CVE-2026-11289MEDIUMSide-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a EPSS 0.2%CVE-2026-55227MEDIUMObservable object existence disclosure in private Weblate projects via globally scoped object lookupsEPSS 0.2%CVE-2025-54999LOWOpenBao: Timing Side-Channel in Userpass Auth MethodEPSS 0.2%CVE-2026-87619MEDIUMObservable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a craftedEPSS 0.2%CVE-2026-23620MEDIUMGFI MailEssentials AI < 22.4 ListServer.IsDBExist() Absolute Directory Traversal to File EnumerationEPSS 0.2%CVE-2026-21386MEDIUMPrivate channel enumeration via /mute slash commandEPSS 0.2%