Falhas do tipo CWE-223

12 resultados

Omissão de Informações Relevantes para Segurança

Ocorre quando o software não registra, retorna ou comunica informações críticas sobre eventos de segurança (erros de autenticação, acesso negado, mudanças sensíveis). Sem esses dados, ataques passam despercebidos e investigações de incidente ficam cegas, porque não há trilha de auditoria.

Exemplo

Um sistema de login falha silenciosamente em tentar gravar tentativas falhadas de autenticação nos logs, ou uma API não documenta qual usuário fez uma alteração de permissões. Quando ocorre um ataque, não há como rastrear quem foi ou quantas tentativas foram feitas.

Como mitigar

Implemente logs detalhados e obrigatórios de eventos sensíveis (autenticação, autorização, mudanças de dados críticos), com timestamp e contexto do ator. Verifique regularmente se os logs estão sendo gerados e armazenados de forma íntegra e imutável, e centralize-os em um SIEM ou sistema de auditoria isolado.

CVE-2023-28360MEDIUMAn omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file tEPSS 0.8%CVE-2024-52813MEDIUMmatrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identityEPSS 0.5%CVE-2026-91859MEDIUMMISP Access Log Entry Overwritten by Error Controller's Second beforeFilter PassEPSS 0.5%CVE-2022-44646LOWIn JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settingsEPSS 0.4%CVE-2023-31191CRITICALDenial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark InnovationsEPSS 0.4%CVE-2023-29156MEDIUMDenial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark InnovationsEPSS 0.3%CVE-2022-22563MEDIUMDell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vuEPSS 0.2%CVE-2025-52926LOWIn scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface.EPSS 0.2%CVE-2026-90955MEDIUMMISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model LoadEPSS 0.2%CVE-2026-31890MEDIUMInspektor Gadget: Tracing Denial of Service via Event FloodingEPSS 0.1%CVE-2026-49426LOWIncorrect audit records for ptrace(2) syscall requestsEPSS 0.1%CVE-2025-35987MEDIUMOmission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: KernEPSS 0.1%