Falhas do tipo CWE-204

188 resultados

Vazamento de informações por respostas diferenciadas

A aplicação retorna respostas diferentes (tempo de resposta, mensagens de erro, códigos HTTP, comportamento) para requisições distintas, permitindo que um atacante deduza informações internas (existência de usuários, estrutura do sistema, dados sensíveis) sem ter acesso autorizado. O risco está em cada diferença na resposta servir como pista que reduz o espaço de busca do ataque.

Exemplo

Um endpoint de login retorna 'usuário não encontrado' para emails inexistentes, mas 'senha incorreta' para emails válidos. Um atacante usa isso para enumerar contas ativas no sistema. Ou um sistema que demora 200ms para validar senhas corretas e 50ms para incorretas, permitindo adivinhação via timing.

Como mitigar

Padronize respostas para casos de erro (mesmo tempo, mesma mensagem genérica) e implemente rate limiting em operações sensíveis. Use bcrypt com custo fixo para autenticação e evite diferenciar comportamento baseado em dados internos não-públicos.

CVE-2025-66307MEDIUMGrav Admin Plugin vulnerable to User Enumeration & Email DisclosureEPSS 0.3%CVE-2025-3939MEDIUMObservable Response DiscrepancyEPSS 0.3%CVE-2026-27462HIGHCombodo iTop: User enumeration via password resetEPSS 0.3%CVE-2025-46390HIGHCWE-204: Observable Response DiscrepancyEPSS 0.3%CVE-2025-58442MEDIUMSaleor has user enumeration vulnerability due to different error messagesEPSS 0.3%CVE-2025-62236MEDIUMFrontier Airlines publicly available email address validationEPSS 0.3%CVE-2024-56476MEDIUMIBM TXSeries for Multiplatforms information disclosureEPSS 0.3%CVE-2026-47083MEDIUMAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH comEPSS 0.3%CVE-2025-12455MEDIUMUsername Enumeration Observable Response Discrepancy vulnerability has been discovered in OpenText™ Vertica.EPSS 0.3%CVE-2026-19080HIGHUsername Enumeration in Menulux Software's Menulux PortalEPSS 0.3%CVE-2023-37413MEDIUMIBM Aspera Faspex information disclosureEPSS 0.3%CVE-2025-12994MEDIUMMedtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that coEPSS 0.3%CVE-2026-26744MEDIUMA user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpEPSS 0.3%CVE-2026-24468MEDIUMOpenAEV Vulnerable to Username/Email Enumeration Through Differential HTTP Responses in Password Reset APIEPSS 0.3%CVE-2026-84307LOWFilament: Password validity disclosure for accounts denied panel access on login pageEPSS 0.3%CVE-2026-24332MEDIUMDiscord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because EPSS 0.3%CVE-2026-54445MEDIUMVantage6: Set admin user and password from environment or configurationEPSS 0.3%CVE-2026-4045MEDIUMprojectsend Auth.php response discrepancyEPSS 0.3%CVE-2026-8242MEDIUMIndustrial Application Software IAS Canias ERP Login RMI doAction response discrepancyEPSS 0.3%CVE-2025-52899MEDIUMTuleap vulnerable to user enumeration via the lost password formEPSS 0.3%