Falhas do tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2022-31697MEDIUMThe vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with aEPSS 0.1%CVE-2024-10523MEDIUMInformation Disclosure Vulnerability in TP-Link IoT Smart HubEPSS 0.1%CVE-2025-23291LOWNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized actioEPSS 0.1%CVE-2020-10706MEDIUMA flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This fEPSS 0.1%CVE-2023-32483MEDIUM Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerability. An authenticated malicious user havinEPSS 0.1%CVE-2025-32353HIGHKaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuraEPSS 0.1%CVE-2024-55582MEDIUMOxide before 6 has unencrypted Control Plane datastores.EPSS 0.1%CVE-2022-48310MEDIUMAn information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versionEPSS 0.1%CVE-2023-39210MEDIUMCleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an informaEPSS 0.1%CVE-2021-35526MEDIUMStorage of Sensitive Information Vulnerability in Hitachi ABB Power Grids System Data Manager – SDM600 ProductEPSS 0.1%CVE-2022-34910MEDIUMAn issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. HoweEPSS 0.1%CVE-2025-53758MEDIUMDefault Credential Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.1%CVE-2024-25661HIGHIn Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop applicatEPSS 0.1%CVE-2026-6332MEDIUMClear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVACEPSS 0.1%CVE-2022-42284MEDIUMNVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.EPSS 0.1%CVE-2026-9274MEDIUMInformation Exposure Vulnerability in CP-Plus Wi-Fi CameraEPSS 0.1%CVE-2026-4346MEDIUMCleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Link's TL-WR850NEPSS 0.1%CVE-2025-48463LOWUnencrypted HTTP CommunicationEPSS 0.1%CVE-2023-32447MEDIUM Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local acEPSS 0.1%CVE-2023-32455MEDIUM Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious uEPSS 0.1%