Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2024-54127MEDIUMExposure of Wi-Fi Credentials in Plaintext in TP-Link Archer C50EPSS 0.2%CVE-2024-9991HIGHCleartext Storage of Sensitive Information Vulnerability in Philips Lighting DevicesEPSS 0.2%CVE-2020-10053A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data,EPSS 0.2%CVE-2025-12679HIGHPlain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0EPSS 0.2%CVE-2024-12094MEDIUMInformation Disclosure Vulnerability in TinxyEPSS 0.2%CVE-2026-82699MEDIUMsambitraj Student Management System Password aca.sql cleartext storageEPSS 0.2%CVE-2025-50777HIGHThe firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerabEPSS 0.2%CVE-2025-0418MEDIUMValmet DNA user passwords in plain textEPSS 0.2%CVE-2026-3221MEDIUMSensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker wEPSS 0.2%CVE-2024-56362HIGHNavidrome Stores JWT Secret in Plaintext in navidrome.dbEPSS 0.2%CVE-2024-56428MEDIUMThe local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for thEPSS 0.2%CVE-2026-38571MEDIUMCleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticatEPSS 0.2%CVE-2026-76383MEDIUMInformation Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAREPSS 0.2%CVE-2026-65599MEDIUMn8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT HeaderEPSS 0.2%CVE-2026-45040MEDIUMRustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]EPSS 0.2%CVE-2026-6598MEDIUMlangflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in fileEPSS 0.2%CVE-2024-41691HIGHInsecure Storage of Sensitive Information VulnerabilityEPSS 0.2%CVE-2024-41690HIGHDefault Credential Storage in Plaintext VulnerabilityEPSS 0.2%CVE-2026-33867CRITICALAVideo has Plaintext Video Password StorageEPSS 0.2%CVE-2023-29471MEDIUMLightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clearEPSS 0.2%