Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2026-43824HIGHIn Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.EPSS 0.2%CVE-2024-8689MEDIUMActiveMQ Content Pack: Cleartext Exposure of CredentialsEPSS 0.2%CVE-2024-45744LOWTopQuadrant TopBraid EDG password manager stores external credentials insecurelyEPSS 0.2%CVE-2023-28912MEDIUMCleartext Phonebook InformationEPSS 0.2%CVE-2024-31587MEDIUMSecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a EPSS 0.2%CVE-2020-7517A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow EPSS 0.2%CVE-2026-86280MEDIUMSourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storageEPSS 0.2%CVE-2025-7738MEDIUMPython3.11-django-ansible-base: sensitive authenticator secrets returned in clear text via api in aapEPSS 0.2%CVE-2024-36589MEDIUMAn issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd81EPSS 0.2%CVE-2020-25677A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allowEPSS 0.2%CVE-2025-1499MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.2%CVE-2026-61928MEDIUMWindows Hello Tampering VulnerabilityEPSS 0.2%CVE-2024-35117MEDIUMIBM OpenPages with Watson information disclosureEPSS 0.2%CVE-2024-24488MEDIUMAn issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password cEPSS 0.2%CVE-2025-53742MEDIUMJenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, EPSS 0.2%CVE-2026-32842HIGHEdimax GS-5008PL <= 1.00.54 Admin Credentials Stored in CleartextEPSS 0.2%CVE-2026-41385HIGHOpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction BypassEPSS 0.2%CVE-2022-39351MEDIUMDependency-Track vulnerable to logging of API keys in clear text when handling API requests using keys with insufficient permissionsEPSS 0.2%CVE-2021-22509HIGHHandling of sensitive data in process memory in NetIQ Advance AuthenticationEPSS 0.2%CVE-2026-59657HIGHApache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJobEPSS 0.2%