Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2026-20312HIGHCisco Catalyst SD-WAN Security Hardening Release - Information Disclosure VulnerabilitiesEPSS 0.3%CVE-2024-7259MEDIUMOvirt-engine: potential exposure of cleartext provider passwords via web uiEPSS 0.3%CVE-2025-10464MEDIUMCleartext password storage in Birtech Information Technologies' SensawayEPSS 0.3%CVE-2025-54538MEDIUMIn JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" commandEPSS 0.3%CVE-2025-54537MEDIUMIn JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshotsEPSS 0.3%CVE-2021-33716A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1EPSS 0.3%CVE-2025-46633HIGHCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt EPSS 0.3%CVE-2023-3950MEDIUMCleartext Storage of Sensitive Information in GitLabEPSS 0.3%CVE-2024-45862HIGHCleartext Storage of Sensitive Information in Kastle Systems Access Control SystemEPSS 0.2%CVE-2023-48305MEDIUMNextcloud Server user_ldap app logs user passwords in the log file on level debugEPSS 0.2%CVE-2026-63406MEDIUMAnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including SecretsEPSS 0.2%CVE-2025-65320HIGHAbacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The applicatEPSS 0.2%CVE-2025-63208HIGHAn issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive EPSS 0.2%CVE-2023-41964MEDIUMBIG-IP and BIG-IQ Database Variable vulnerabilityEPSS 0.2%CVE-2023-31925MEDIUMStorage of clear text password in Brocade SANnavEPSS 0.2%CVE-2024-6921HIGHCleartext Username and Password in NAC Telecommunication's NACPremiumEPSS 0.2%CVE-2025-55443CRITICALTelpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stEPSS 0.2%CVE-2022-47512MEDIUMSensitive Data Disclosure VulnerabilityEPSS 0.2%CVE-2025-65278HIGHAn issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive iEPSS 0.2%CVE-2018-19009Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti EPSS 0.2%