Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2025-45001HIGHreact-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaEPSS 0.2%CVE-2026-7163MEDIUMAssisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosureEPSS 0.2%CVE-2025-59701MEDIUMEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.2%CVE-2026-35644HIGHOpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway SnapshotsEPSS 0.2%CVE-2025-14377HIGHVerve Asset Manager – Plaintext Storage VulnerabilitiesEPSS 0.2%CVE-2024-39846LOWNewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitiEPSS 0.2%CVE-2025-12774MEDIUMSQL queries with sensitive information printed in logs with Brocade SANnav before 3.0EPSS 0.2%CVE-2022-35120HIGHIXPdata EasyInstall 6.6.14725 contains an access control issue.EPSS 0.2%CVE-2025-4394MEDIUMMedtronic MyCareLink Patient Monitor Unencrypted Filesystem VulnerabilityEPSS 0.2%CVE-2024-38877HIGHA vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All verEPSS 0.2%CVE-2025-56565HIGHDD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within noEPSS 0.2%CVE-2025-46820HIGHphpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifactEPSS 0.2%CVE-2021-3551A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log fiEPSS 0.2%CVE-2024-25658MEDIUMCleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the daEPSS 0.2%CVE-2022-24120MEDIUMCertain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.EPSS 0.2%CVE-2025-67637MEDIUMJenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins contEPSS 0.2%CVE-2026-77975HIGHEbyte NA111-M Cleartext Storage of Sensitive InformationEPSS 0.2%CVE-2025-56566MEDIUMMikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attackerEPSS 0.2%CVE-2023-49113HIGHSensitive Data Stored Insecurely in Kiuwan SAST Local AnalyzerEPSS 0.2%CVE-2021-27487ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker toEPSS 0.2%