Falhas do tipo CWE-294

213 resultados

Exposição de informações sensíveis a atores não autorizados

Fraqueza na qual dados sensíveis (credenciais, chaves, PII, tokens) são acessíveis por usuários ou processos que não deveriam ter acesso. Ocorre por falhas em controle de acesso, armazenamento inadequado ou transmissão desprotegida, permitindo vazamento ou roubo dessas informações.

Exemplo

Uma aplicação grava tokens de autenticação em logs em texto plano acessíveis via endpoint público, ou armazena senhas sem hash em banco de dados com permissões leitura aberta. Um atacante consegue ler essas credenciais e impersonar usuários legítimos.

Como mitigar

Implemente controle de acesso rigoroso baseado em papéis (RBAC/ABAC), criptografe dados sensíveis em repouso e em trânsito (TLS, AES), nunca registre credenciais em logs, e revise regularmente permissões de arquivos e endpoints para garantir que apenas atores autorizados acessem informações críticas.

CVE-2022-41541HIGHTP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message and EPSS 1.2%CVE-2026-69676HIGHWindows Kerberos Remote Code Execution VulnerabilityEPSS 1.2%CVE-2022-42731HIGHmfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a uEPSS 1.1%CVE-2022-29878HIGHA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent duriEPSS 1.1%CVE-2020-10045A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An error EPSS 1.1%CVE-2020-25660A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients coEPSS 1.0%CVE-2020-5300MEDIUMDisallow replay of `private_key_jwt` by blacklisting JTIs in HydraEPSS 1.0%CVE-2021-38459HIGHAUVESY VersiondogEPSS 1.0%CVE-2020-14302A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endEPSS 1.0%CVE-2020-4042MEDIUMAuthentication bypass in BareosEPSS 1.0%CVE-2024-29851HIGHVeeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.EPSS 0.9%CVE-2025-49752CRITICALAzure Bastion Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-1886HIGHAuthentication Bypass by Capture-replay in thorsten/phpmyfaqEPSS 0.9%CVE-2019-13533HIGHIn Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the contrEPSS 0.9%CVE-2021-27289CRITICALA replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = EPSS 0.9%CVE-2022-36089HIGHVelaUX APIServer vulnerable to Authentication Bypass by Capture-replayEPSS 0.9%CVE-2021-27662HIGHKT-1 Capture-replayEPSS 0.8%CVE-2023-1537MEDIUMAuthentication Bypass by Capture-replay in answerdev/answerEPSS 0.8%CVE-2022-31158HIGHAuthentication Bypass by Capture-replay in packbackbooks/lti-1-3-php-libraryEPSS 0.8%CVE-2022-22936HIGHAn issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible tEPSS 0.8%