Falhas do tipo CWE-212

78 resultados

Divulgação não intencional de informações sensíveis

A aplicação expõe dados confidenciais (senhas, tokens, chaves, dados pessoais) através de canais ou contextos onde não deveriam estar acessíveis. O risco está em um invasor conseguir essas informações sem autenticação ou autorização adequadas, comprometendo a confidencialidade do sistema.

Exemplo

Uma API retorna a senha hash do usuário em resposta de erro, ou logs de produção contêm tokens de API visíveis em páginas de diagnóstico não protegidas, ou cookies de sessão aparecem em URLs refletidas em mensagens de erro.

Como mitigar

Implemente sanitização rigorosa de saídas (erros, logs, respostas HTTP), nunca exponha dados sensíveis em mensagens de erro ou debug, restrinja acesso a ferramentas diagnósticas com autenticação forte e revise regularmente logs e responses da API para dados confidenciais.

CVE-2025-57757MEDIUMContao discloses information in the news moduleEPSS 0.3%CVE-2026-82069MEDIUMImproper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster RouterEPSS 0.3%CVE-2026-27640HIGHtfplan2md has Sensitive Value Exposure in Generated ReportsEPSS 0.3%CVE-2025-59955MEDIUMCoolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpointEPSS 0.3%CVE-2024-32028MEDIUMSensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCoreEPSS 0.3%CVE-2026-54421MEDIUMIn OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can returnEPSS 0.3%CVE-2024-29120MEDIUMApache StreamPark: Information leakage vulnerabilityEPSS 0.3%CVE-2026-78658MEDIUMIBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerabilityEPSS 0.3%CVE-2026-46657HIGHBludit's persistent authentication tokens not revoked upon account disablementEPSS 0.3%CVE-2025-62483MEDIUMZoom Clients - Improper Removal of Sensitive InformationEPSS 0.3%CVE-2026-39937HIGHGlobal vanishing does not completely remove user emailEPSS 0.3%CVE-2021-33082MEDIUMSensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and Intel(R) Optane(TM) SSD Products may allow EPSS 0.3%CVE-2021-33080MEDIUMExposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD anEPSS 0.3%CVE-2026-16104MEDIUMKeycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only adminsEPSS 0.3%CVE-2026-73440LOWSecurity Advisory 0178EPSS 0.3%CVE-2026-1732MEDIUMImproper Removal of Sensitive Information Before Storage or Transfer in GitLabEPSS 0.3%CVE-2026-42186LOWOpenBao's Namespace Deletion May Not Delete Data ProperlyEPSS 0.2%CVE-2026-85094HIGHThe Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat EPSS 0.2%CVE-2026-27892MEDIUMFacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/DownloadEPSS 0.2%CVE-2026-43824HIGHIn Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.EPSS 0.2%