Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2020-29501MEDIUMDell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A EPSS 0.2%CVE-2021-38422HIGHDelta Electronics DIALinkEPSS 0.2%CVE-2024-28809HIGHAn issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers tEPSS 0.2%CVE-2022-45154MEDIUMsupportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.shEPSS 0.2%CVE-2023-40715MEDIUMA cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access toEPSS 0.2%CVE-2026-15721CRITICALQuery Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human ResourcesEPSS 0.2%CVE-2023-37468MEDIUMStoring unencrypted LDAP passwords in feedbacksystemEPSS 0.2%CVE-2022-28214During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are beinEPSS 0.2%CVE-2025-32752MEDIUMDell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacker with physical acceEPSS 0.2%CVE-2026-39943MEDIUMDirectus exposes sensitive fields in revision historyEPSS 0.2%CVE-2026-34833HIGHBulwark Webmail: Information Exposure: password returned in /api/auth/sessionEPSS 0.2%CVE-2025-70050MEDIUMAn issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 which allows attackersEPSS 0.2%CVE-2026-6553HIGHTYPO3 CMS Stores Cleartext Password in User Settings ModuleEPSS 0.2%CVE-2018-16498In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These EPSS 0.2%CVE-2025-46634HIGHCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated aEPSS 0.2%CVE-2024-45718MEDIUMSensitive data disclosure vulnerabilityEPSS 0.2%CVE-2024-53651MEDIUMA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CEPSS 0.2%CVE-2025-2181MEDIUMCheckov by Prisma Cloud: Cleartext Exposure of CredentialsEPSS 0.2%CVE-2026-3277MEDIUMThe OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext iEPSS 0.2%CVE-2025-67638MEDIUMJenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasEPSS 0.2%