Falhas do tipo CWE-212

77 resultados

Divulgação não intencional de informações sensíveis

A aplicação expõe dados confidenciais (senhas, tokens, chaves, dados pessoais) através de canais ou contextos onde não deveriam estar acessíveis. O risco está em um invasor conseguir essas informações sem autenticação ou autorização adequadas, comprometendo a confidencialidade do sistema.

Exemplo

Uma API retorna a senha hash do usuário em resposta de erro, ou logs de produção contêm tokens de API visíveis em páginas de diagnóstico não protegidas, ou cookies de sessão aparecem em URLs refletidas em mensagens de erro.

Como mitigar

Implemente sanitização rigorosa de saídas (erros, logs, respostas HTTP), nunca exponha dados sensíveis em mensagens de erro ou debug, restrinja acesso a ferramentas diagnósticas com autenticação forte e revise regularmente logs e responses da API para dados confidenciais.

CVE-2026-67071MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or TransferEPSS 0.2%CVE-2025-65000LOWExposure of SSH Private Keys in Remote Alert Handlers (Linux) RuleEPSS 0.2%CVE-2026-86740MEDIUMSnipe-IT before 8.7.0 Attachment Deletion Reports Success While File RemainsEPSS 0.2%CVE-2025-24884MEDIUMkube-audit-rest's example logging configuration could disclose secret values in the audit logEPSS 0.2%CVE-2026-34214HIGHTrino: Iceberg REST catalog static and vended credentials are accessible via query JSONEPSS 0.2%CVE-2026-1182MEDIUMImproper Removal of Sensitive Information Before Storage or Transfer in GitLabEPSS 0.2%CVE-2025-64326LOWWeblate leaks the IP of project members inviting users to assume reviewer roles in Audit logEPSS 0.2%CVE-2025-0011LOWImproper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address EPSS 0.2%CVE-2026-32891CRITICALAnchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSEPSS 0.2%CVE-2025-20118MEDIUMCisco Application Policy Infrastructure Controller Authenticated Command Injection Due to Sensitive Disclosure VulnerabilityEPSS 0.2%CVE-2025-8860LOWQemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callbackEPSS 0.2%CVE-2025-65965HIGHGrype has a credential disclosure vulnerability in Grype JSON outputEPSS 0.1%CVE-2026-36178MEDIUMThe factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, poEPSS 0.1%CVE-2026-53604HIGHnebula-mesh: CA private key not zeroized on web mobile-bundle error pathsEPSS 0.1%CVE-2026-45046MEDIUMGryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive ContentEPSS 0.1%CVE-2024-5300MEDIUMAppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbdEPSS 0.1%CVE-2026-15811MEDIUMKronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changesEPSS 0.1%