Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2024-40490HIGHAn issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot PassEPSS 0.5%CVE-2026-64713HIGHThis issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, viEPSS 0.5%CVE-2024-2464MEDIUMApplication users enumeration in CDeXEPSS 0.5%CVE-2026-26315MEDIUMGo Ethereum Improperly Validates the ECIES Public Key in RLPx HandshakeEPSS 0.5%CVE-2026-56339HIGHCapgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPCEPSS 0.5%CVE-2022-4025MEDIUMInappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an EPSS 0.5%CVE-2023-33518MEDIUMemoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory pEPSS 0.5%CVE-2024-41335HIGHDraytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior EPSS 0.5%CVE-2024-11084MEDIUMPotential Username Enumeration in Helix ALMEPSS 0.5%CVE-2023-28015MEDIUMHCL Domino AppDev Pack is susceptible to a User Account Enumeration vulnerabilityEPSS 0.4%CVE-2023-34344MEDIUMA vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid usernameEPSS 0.4%CVE-2024-31878MEDIUMIBM i information disclosureEPSS 0.4%CVE-2023-1696HIGHThe multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability.EPSS 0.4%CVE-2024-21206MEDIUMVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versEPSS 0.4%CVE-2026-78955MEDIUMObservable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origEPSS 0.4%CVE-2024-12663MEDIUMfunnyzpc Mee-Admin Login login observable response discrepancyEPSS 0.4%CVE-2024-28885HIGHObservable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network aEPSS 0.4%CVE-2026-47379MEDIUMNocoDB: Plaintext Password Comparison in Shared ViewsEPSS 0.4%CVE-2024-39921HIGHObservable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to VEPSS 0.4%CVE-2026-64822MEDIUMdjangoSIGE 1.10 User Enumeration via ForgotPasswordViewEPSS 0.4%