Falhas do tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2023-32455MEDIUM Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious uEPSS 0.1%CVE-2025-34428HIGHMailEnable < 10.54 Cleartext Credential Storage in AUTH.SAVEPSS 0.1%CVE-2023-32448MEDIUM PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the instEPSS 0.1%CVE-2025-0123MEDIUMPAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet CapturesEPSS 0.1%CVE-2024-31415MEDIUMThe Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network manageEPSS 0.1%CVE-2024-47056MEDIUMMautic does not shield .env files from web trafficEPSS 0.1%CVE-2022-4312MEDIUM A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized uEPSS 0.1%CVE-2023-39440MEDIUMInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence PlatformEPSS 0.1%CVE-2025-2182MEDIUMPAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK)EPSS 0.1%CVE-2025-34427HIGHMailEnable < 10.54 Cleartext Credential Storage in AUTH.TABEPSS 0.1%CVE-2023-46294LOWAn issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwEPSS 0.1%CVE-2024-25023MEDIUMIBM QRadar Suite Software information disclosureEPSS 0.1%CVE-2025-27460HIGHCVE-2025-27460EPSS 0.1%CVE-2024-28807MEDIUMAn issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop managementEPSS 0.1%CVE-2024-29954MEDIUMpassword management API prints sensitive information in log filesEPSS 0.1%CVE-2024-23942HIGHMB connect line: Configuration File on the client workstation is not encryptedEPSS 0.1%CVE-2024-8070HIGHCWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binaryEPSS 0.1%CVE-2024-29952MEDIUMClear text storage of sensistive information by manipulating command variables EPSS 0.1%CVE-2026-21080MEDIUMCleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.EPSS 0.1%CVE-2024-51993LOWPassword is stored in clear in the database in Combodo iTopEPSS 0.1%