Falhas do tipo CWE-209

426 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação expõe detalhes técnicos internos (caminhos de arquivos, versões de banco de dados, stack traces, credenciais) em mensagens de erro exibidas ao usuário. Um atacante usa essas informações para mapear a infraestrutura, identificar versões vulneráveis e planejar ataques mais precisos.

Exemplo

Um aplicativo PHP exibe erro de conexão com banco: 'Fatal error: Cannot connect to MySQL at /var/www/html/db.php line 42, user: root@192.168.1.5'. O atacante descobre o caminho do servidor, versão do MySQL, IP interno e usuário administrativo — tudo que precisa para explorar o sistema.

Como mitigar

Exiba mensagens genéricas ao usuário ('Erro ao processar requisição') e registre os detalhes reais em logs do servidor que só administradores acessam. Configure o ambiente de produção para desabilitar stack traces visíveis (debug=false em frameworks).

CVE-2024-27315MEDIUMApache Superset: Improper error handling on alertsEPSS 1.0%CVE-2022-0079MEDIUMGeneration of Error Message Containing Sensitive Information in star7th/showdocEPSS 1.0%CVE-2026-67383MEDIUMMicrosoft SQL Server Information Disclosure VulnerabilityEPSS 1.0%CVE-2023-37260HIGHleague/oauth2-server key exposed in exception message when passing as string and providing invalid pass phraseEPSS 1.0%CVE-2025-23320HIGHNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause the shareEPSS 0.9%CVE-2021-35251MEDIUMSensitive Data Disclosure VulnerabilityEPSS 0.9%CVE-2023-40171CRITICALDispatch writes JWT tokens in error messageEPSS 0.9%CVE-2021-4177MEDIUMGeneration of Error Message Containing Sensitive Information in livehelperchat/livehelperchatEPSS 0.9%CVE-2017-0885Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in EPSS 0.9%CVE-2022-0083HIGHGeneration of Error Message Containing Sensitive Information in livehelperchat/livehelperchatEPSS 0.9%CVE-2026-69552MEDIUMWindows Print Spooler Components Information Disclosure VulnerabilityEPSS 0.9%CVE-2024-21619MEDIUMJunos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive informationEPSS 0.9%CVE-2018-10624MEDIUMJohnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive InformationEPSS 0.9%CVE-2022-34882CRITICALInformation Exposure Vulnerability in RAID Manager Storage Replication AdapterEPSS 0.9%CVE-2024-53948MEDIUMApache Superset: Error verbosity exposes metadata in analytics databasesEPSS 0.9%CVE-2023-49080LOWJupyter Server errors include tracebacks with path informationEPSS 0.8%CVE-2023-22626HIGHPgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on databaEPSS 0.8%CVE-2023-26051MEDIUMSaleor is vulnerable to staff-authenticated error message information disclosure vulnerability via Python exceptionsEPSS 0.8%CVE-2024-47803MEDIUMJenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissionsEPSS 0.8%CVE-2024-45384MEDIUMApache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle AttackEPSS 0.8%