Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2026-59657HIGHApache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJobEPSS 0.2%CVE-2024-9802MEDIUMConformance validation endpoint discloses detail about service to unauthenticated usersEPSS 0.2%CVE-2026-5531MEDIUMSourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in fileEPSS 0.2%CVE-2026-53603HIGHnebula-mesh: Operator session tokens stored in plaintext in the databaseEPSS 0.2%CVE-2023-24454MEDIUMJenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on tEPSS 0.2%CVE-2023-24439MEDIUMJenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file onEPSS 0.2%CVE-2020-7516A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allowEPSS 0.2%CVE-2025-14836MEDIUMZZCMS User Data Storage user_save.php cleartext storage in fileEPSS 0.2%CVE-2026-90842MEDIUMPHPGurukul Blood Donor Management System Login_Model.php cleartext storage in fileEPSS 0.2%CVE-2026-81321CRITICALCareCam CM2507 Cleartext Storage of Sensitive InformationEPSS 0.2%CVE-2025-5154MEDIUMPhonePe App SQLite Database databases cleartext storage in a file or on diskEPSS 0.2%CVE-2020-29500HIGHDell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locaEPSS 0.2%CVE-2020-29502HIGHDell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A EPSS 0.2%CVE-2026-46622HIGHSolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breachEPSS 0.2%CVE-2026-27520HIGHBinardat 10G08-0800GSM Network Switch Base64-encoded Password Stored in CookieEPSS 0.2%CVE-2024-4840MEDIUMRhosp-director: cleartext passwords exposed in logsEPSS 0.2%CVE-2022-45439MEDIUMA pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. EPSS 0.2%CVE-2026-34214HIGHTrino: Iceberg REST catalog static and vended credentials are accessible via query JSONEPSS 0.2%CVE-2026-47702CRITICALTypeBot API tokens stored in plaintextEPSS 0.2%CVE-2026-57287MEDIUMJenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying hiEPSS 0.2%