Falhas do tipo CWE-294

211 resultados

Exposição de informações sensíveis a atores não autorizados

Fraqueza na qual dados sensíveis (credenciais, chaves, PII, tokens) são acessíveis por usuários ou processos que não deveriam ter acesso. Ocorre por falhas em controle de acesso, armazenamento inadequado ou transmissão desprotegida, permitindo vazamento ou roubo dessas informações.

Exemplo

Uma aplicação grava tokens de autenticação em logs em texto plano acessíveis via endpoint público, ou armazena senhas sem hash em banco de dados com permissões leitura aberta. Um atacante consegue ler essas credenciais e impersonar usuários legítimos.

Como mitigar

Implemente controle de acesso rigoroso baseado em papéis (RBAC/ABAC), criptografe dados sensíveis em repouso e em trânsito (TLS, AES), nunca registre credenciais em logs, e revise regularmente permissões de arquivos e endpoints para garantir que apenas atores autorizados acessem informações críticas.

CVE-2024-29901MEDIUM@workos-inc/authkit-nextjs session replay vulnerabilityEPSS 0.7%CVE-2023-39547CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleEPSS 0.6%CVE-2023-47435CRITICALAn issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected EPSS 0.6%CVE-2024-40715HIGHA vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypasEPSS 0.6%CVE-2023-41890HIGHSustainsys.Saml2 Insufficient Identity Provider Issuer ValidationEPSS 0.6%CVE-2024-45244MEDIUMHyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.EPSS 0.6%CVE-2021-38827HIGHXiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover.EPSS 0.6%CVE-2022-29475MEDIUMAn information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9EPSS 0.6%CVE-2023-29158MEDIUMSUBNET PowerSYSTEM Center Authentication Bypass by Capture-replayEPSS 0.6%CVE-2025-26201CRITICALCredential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentEPSS 0.6%CVE-2022-2780HIGHIn affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB requesEPSS 0.6%CVE-2025-30072HIGHTiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities withEPSS 0.6%CVE-2026-55250HIGHMaravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged CachesEPSS 0.6%CVE-2026-57574HIGHMisskey: TOTP tokens can be reusedEPSS 0.6%CVE-2024-49595HIGHDell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged EPSS 0.5%CVE-2025-9100MEDIUMzhenfeng13 My-Blog Frontend Blog Article Comment comment authentication replayEPSS 0.5%CVE-2025-6533MEDIUMxxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replayEPSS 0.5%CVE-2026-51597CRITICALMERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent netEPSS 0.5%CVE-2022-47930MEDIUMAn issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implemenEPSS 0.5%CVE-2017-5251In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices areEPSS 0.5%