Falhas do tipo CWE-213

33 resultados

Exposição de informações sensíveis por políticas incompatíveis

A aplicação expõe dados sensíveis porque diferentes componentes, sistemas ou camadas aplicam políticas de segurança conflitantes ou inconsistentes. Um componente pode proteger a informação, mas outro a expõe sem as mesmas restrições, criando uma brecha de segurança que o atacante explora passando pela camada menos rigorosa.

Exemplo

Uma API retorna tokens de autenticação em resposta de erro quando a validação de entrada falha, enquanto a política de segurança exige que dados sensíveis nunca apareçam em mensagens de erro. A falta de alinhamento entre o desenvolvedor e a política resulta na exposição do token a logs ou ao cliente.

Como mitigar

Alinhe políticas de segurança em todos os componentes (API, banco de dados, frontend, logs) e valide a implementação em testes. Use uma camada de sanitização centralizada para garantir que mensagens de erro, logs e respostas nunca contenham dados sensíveis, independentemente de quem as produz.

CVE-2019-10247In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version EPSS 5.9%CVE-2019-10246In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base ResEPSS 4.1%CVE-2019-1010283Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. ThEPSS 1.4%CVE-2025-54831MEDIUMApache Airflow: Connection sensitive details exposed to users with READ permissionsEPSS 0.9%CVE-2017-3211MEDIUMCentire Yopify leaks customer informationEPSS 0.8%CVE-2022-22541SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see EPSS 0.8%CVE-2020-1652MEDIUMJunos Space: OpenNMS is accessible via port 9443EPSS 0.7%CVE-2022-30350HIGHAvanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides usEPSS 0.7%CVE-2024-7267HIGHInternal infrastructure data leak in EZD RPEPSS 0.6%CVE-2023-40570MEDIUMDatasette 1.0 alpha series leaks names of databases and tables to unauthenticated usersEPSS 0.6%CVE-2023-3441MEDIUMExposure of Sensitive Information Due to Incompatible Policies in GitLabEPSS 0.6%CVE-2023-36919MEDIUMInformation Disclosure in SAP Enable NowEPSS 0.5%CVE-2023-6517HIGHSeeing the SMS Verification Code in Mia Technology's Mia-MedEPSS 0.5%CVE-2025-4976MEDIUMExposure of Sensitive Information Due to Incompatible Policies in GitLabEPSS 0.4%CVE-2026-6280MEDIUMImproper Access Control in Nomysoft Informatics' NomysemEPSS 0.4%CVE-2026-33216HIGHNATS has MQTT plaintext password disclosureEPSS 0.4%CVE-2024-49354MEDIUMIBM Concert information disclosureEPSS 0.3%CVE-2023-5117LOWExposure of Sensitive Information Due to Incompatible Policies in GitLabEPSS 0.3%CVE-2025-24316MEDIUMDario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible PoliciesEPSS 0.3%CVE-2026-55425MEDIUMGraylog: System Catalog titles endpoint can be used to retrieve values of protected database fieldsEPSS 0.3%