Falhas do tipo CWE-209

432 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação expõe detalhes técnicos internos (caminhos de arquivos, versões de banco de dados, stack traces, credenciais) em mensagens de erro exibidas ao usuário. Um atacante usa essas informações para mapear a infraestrutura, identificar versões vulneráveis e planejar ataques mais precisos.

Exemplo

Um aplicativo PHP exibe erro de conexão com banco: 'Fatal error: Cannot connect to MySQL at /var/www/html/db.php line 42, user: root@192.168.1.5'. O atacante descobre o caminho do servidor, versão do MySQL, IP interno e usuário administrativo — tudo que precisa para explorar o sistema.

Como mitigar

Exiba mensagens genéricas ao usuário ('Erro ao processar requisição') e registre os detalhes reais em logs do servidor que só administradores acessam. Configure o ambiente de produção para desabilitar stack traces visíveis (debug=false em frameworks).

CVE-2025-41076MEDIUMMultiple vulnerabilities in LimesurveyEPSS 0.3%CVE-2026-2752MEDIUMNavtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to EPSS 0.3%CVE-2025-54791MEDIUMOMERO.web displays unecessary user information when requesting to reset the passwordEPSS 0.3%CVE-2025-62397MEDIUMMoodle: router produces json instead of 404 error for invalid course idEPSS 0.3%CVE-2026-74879HIGHopenssl_encrypt before 1.4.0 Information Disclosure via /ready endpointEPSS 0.3%CVE-2025-0049LOWDisclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0EPSS 0.3%CVE-2026-73555MEDIUMvLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error MessagesEPSS 0.3%CVE-2026-43873HIGHWWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone ServerEPSS 0.3%CVE-2025-61959MEDIUMVertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive InformationEPSS 0.3%CVE-2026-28675MEDIUMOpenSift: Sensitive implementation details exposed via raw exception messages and token-returning endpointsEPSS 0.3%CVE-2026-55375MEDIUMcanto-saas-api: OAuth credentials exposed in URL query string and exception messagesEPSS 0.3%CVE-2026-41931MEDIUMVvveb < 1.0.8.2 Information Disclosure via Debug Exception HandlerEPSS 0.2%CVE-2026-47893HIGHSpring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketServiceEPSS 0.2%CVE-2022-22162HIGHJunos OS: A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged inEPSS 0.2%CVE-2026-1262MEDIUMIBM InfoSphere Information Server Information DisclosureEPSS 0.2%CVE-2026-9583MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposureEPSS 0.2%CVE-2026-44002MEDIUMvm2: Host File Path Disclosure via Stack Trace Information LeakEPSS 0.2%CVE-2025-31960MEDIUMHCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting moduleEPSS 0.2%CVE-2026-79777MEDIUMrclone before v1.75.0 Information Disclosure via RC APIEPSS 0.2%CVE-2025-62840HIGHHBS 3 Hybrid Backup SyncEPSS 0.2%