Falhas do tipo CWE-312

469 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2026-19391MEDIUMInsights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archivesEPSS 0.2%CVE-2024-12079MEDIUMECOVACS lawnmowers cleartext storage of anti-theft PINEPSS 0.2%CVE-2022-2513HIGHCleartext Credentials Vulnerability on Hitachi Energy’s Multiple IED Connectivity Packages (IED ConnPacks) and PCM600 ProductsEPSS 0.1%CVE-2025-47820LOWFlock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.EPSS 0.1%CVE-2024-55928MEDIUMClear text secrets returned & Remote system secrets in clear textEPSS 0.1%CVE-2026-10786MEDIUMImproper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain clEPSS 0.1%CVE-2025-6224MEDIUMKey leakage in juju/utils certificatesEPSS 0.1%CVE-2026-6796MEDIUMSanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in fileEPSS 0.1%CVE-2026-5224MEDIUMSensitive Data Exposure in Kriptek Crypto's CryptosimEPSS 0.1%CVE-2026-76378MEDIUMInformation Disclosure through Action Parameters in Cisco Secure Malware Analytics app for Splunk SOAREPSS 0.1%CVE-2025-4053MEDIUMUnauthorized creation of master key in Mifare Classic Be-Tech cardsEPSS 0.1%CVE-2025-2189MEDIUMInformation Disclosure Vulnerability in Tinxy Smart DevicesEPSS 0.1%CVE-2026-76379MEDIUMInformation Disclosure through Action Parameters in Cisco Webex app for Splunk SOAREPSS 0.1%CVE-2024-28327HIGHAsus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify routerEPSS 0.1%CVE-2026-33003MEDIUMJenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they EPSS 0.1%CVE-2025-47824LOWFlock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.EPSS 0.1%CVE-2024-40594LOWThe OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible tEPSS 0.1%CVE-2024-50570MEDIUMA Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 tEPSS 0.1%CVE-2026-76377MEDIUMInformation Disclosure through Action Parameters in Azure AD Graph app for Splunk SOAREPSS 0.1%CVE-2026-76405MEDIUMInformation Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) appEPSS 0.1%