Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2023-26560MEDIUMNorthern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbEPSS 0.5%CVE-2023-6935MEDIUMMarvin Attack vulnerability in SP Math All RSAEPSS 0.5%CVE-2021-45925MEDIUMUsername EnumerationEPSS 0.5%CVE-2022-43412MEDIUMJenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided anEPSS 0.5%CVE-2024-26268MEDIUMUser enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 2EPSS 0.5%CVE-2023-3529MEDIUMRotem Dynamics Rotem CRM OTP URI Interface information exposureEPSS 0.5%CVE-2026-44332MEDIUMFiber: Username Enumeration via Timing Oracle in BasicAuth Default AuthorizerEPSS 0.5%CVE-2023-24598OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the privEPSS 0.5%CVE-2025-31124MEDIUMZitadel allows User Enumeration by loginname attribute normalizationEPSS 0.5%CVE-2023-43623MEDIUMA vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (MendixEPSS 0.5%CVE-2021-46876MEDIUMAn issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existenceEPSS 0.5%CVE-2023-37482MEDIUMThe login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated reEPSS 0.5%CVE-2023-22359MEDIUMUser-enumeration in RestAPIEPSS 0.5%CVE-2023-36325LOWi2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attEPSS 0.5%CVE-2022-26382MEDIUMWhile the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel atEPSS 0.5%CVE-2023-54357HIGHJoomla com_booking 2.4.9 Information Disclosure via Account EnumerationEPSS 0.5%CVE-2024-0436HIGHPrevent timing attack for single-user password checkEPSS 0.5%CVE-2019-19338MEDIUMA flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculativEPSS 0.5%CVE-2024-25651MEDIUMUser enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whetEPSS 0.5%CVE-2024-49358MEDIUMZimaOS vulnerable to Username Enumeration via API ResponsesEPSS 0.5%