Falhas do tipo CWE-204

188 resultados

Vazamento de informações por respostas diferenciadas

A aplicação retorna respostas diferentes (tempo de resposta, mensagens de erro, códigos HTTP, comportamento) para requisições distintas, permitindo que um atacante deduza informações internas (existência de usuários, estrutura do sistema, dados sensíveis) sem ter acesso autorizado. O risco está em cada diferença na resposta servir como pista que reduz o espaço de busca do ataque.

Exemplo

Um endpoint de login retorna 'usuário não encontrado' para emails inexistentes, mas 'senha incorreta' para emails válidos. Um atacante usa isso para enumerar contas ativas no sistema. Ou um sistema que demora 200ms para validar senhas corretas e 50ms para incorretas, permitindo adivinhação via timing.

Como mitigar

Padronize respostas para casos de erro (mesmo tempo, mesma mensagem genérica) e implemente rate limiting em operações sensíveis. Use bcrypt com custo fixo para autenticação e evite diferenciar comportamento baseado em dados internos não-públicos.

CVE-2023-46170MEDIUMIBM DS8900F information disclosureEPSS 0.5%CVE-2023-37217MEDIUM Tadiran Telecom Aeonix - CWE-204: Observable Response DiscrepancyEPSS 0.4%CVE-2023-31186MEDIUMAvaya IX Workforce Engagement - User Enumeration - CWE-204: Observable Response DiscrepancyEPSS 0.4%CVE-2023-40179MEDIUMSilverware Games vulnerable to account enumeration via inconsistent responsesEPSS 0.4%CVE-2024-55198MEDIUMUser Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allowEPSS 0.4%CVE-2025-62181MEDIUMPega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration where during user authentication process, a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.EPSS 0.4%CVE-2023-49069MEDIUMA vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by theEPSS 0.4%CVE-2026-33419CRITICALMinIO: LDAP login brute-force via user enumeration and missing rate limitEPSS 0.4%CVE-2025-3092HIGHMB connect line: Observable response discrepancy in mbCONNECT24/mymbCONNECT24EPSS 0.4%CVE-2026-61503MEDIUMRejetto HFS < 3.2.1 Username Enumeration via Login Response DifferencesEPSS 0.4%CVE-2018-25350CRITICALuserSpice 4.3.24 Username Enumeration via existingUsernameCheck.phpEPSS 0.4%CVE-2026-54739MEDIUMLemmy: Login Endpoint User Enumeration via HTTP Response Code DifferentialEPSS 0.4%CVE-2024-12663MEDIUMfunnyzpc Mee-Admin Login login observable response discrepancyEPSS 0.4%CVE-2025-5485HIGHSinoTrack GPS Receiver Weak AuthenticationEPSS 0.4%CVE-2024-8651MEDIUMNetcat CMS: user enumerationEPSS 0.4%CVE-2019-25338MEDIUMDokuwiki 2018-04-22b - Username EnumerationEPSS 0.4%CVE-2025-24342MEDIUMA vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernaEPSS 0.4%CVE-2026-73306MEDIUMBudibase: Account Enumeration via Login Lockout Response DifferentialEPSS 0.4%CVE-2024-38322MEDIUMIBM Storage Defender information disclosureEPSS 0.4%CVE-2026-23511MEDIUMZITADEL has a user enumeration vulnerability in Login UIsEPSS 0.4%