Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2025-44614HIGHTinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plEPSS 0.2%CVE-2025-49728MEDIUMMicrosoft PC Manager Security Feature Bypass VulnerabilityEPSS 0.2%CVE-2025-44649HIGHIn the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive modEPSS 0.2%CVE-2024-33470MEDIUMAn issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passbacEPSS 0.2%CVE-2019-14890HIGHA vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentiEPSS 0.2%CVE-2025-12680MEDIUMBrocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680)EPSS 0.2%CVE-2026-13380CRITICALVSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP ResponsesEPSS 0.2%CVE-2026-33512HIGHAVideo has an unauthenticated decrypt oracle leaking any ciphertextEPSS 0.2%CVE-2025-25613HIGHFS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 wEPSS 0.2%CVE-2024-9798MEDIUMHealth endpoint offers list of onboarded services to unauthenticated usersEPSS 0.2%CVE-2024-28065MEDIUMIn Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.EPSS 0.2%CVE-2023-31423MEDIUMPossible information exposure through log file vulnerabilityEPSS 0.2%CVE-2026-59244MEDIUMApache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UIEPSS 0.2%CVE-2026-68970MEDIUMApache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UIEPSS 0.2%CVE-2024-52284HIGHRancher Fleet Helm Values are stored inside BundleDeployment in plain textEPSS 0.2%CVE-2023-24442MEDIUMJenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar pEPSS 0.2%CVE-2024-28810MEDIUMAn issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allowsEPSS 0.2%CVE-2024-21993MEDIUMInformation Disclosure Vulnerability in SnapCenterEPSS 0.2%CVE-2019-25279MEDIUMFaceSentry Access Control System 6.4.8 Cleartext Password Storage VulnerabilityEPSS 0.2%CVE-2026-43824HIGHIn Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.EPSS 0.2%