Falhas do tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2024-51993LOWPassword is stored in clear in the database in Combodo iTopEPSS 0.1%CVE-2024-58023HIGHInformation disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.EPSS 0.1%CVE-2024-28024MEDIUMA vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessibEPSS 0.1%CVE-2025-59450MEDIUMThe YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.EPSS 0.1%CVE-2026-16213MEDIUMFantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storageEPSS 0.1%CVE-2024-10404MEDIUMClear text password seen in switch-asset-collectors-mw in Brocade SANnav supportsaveEPSS 0.1%CVE-2025-6748LOWBharti Airtel Thanks App files cleartext storage in a file or on diskEPSS 0.1%CVE-2026-73748LOWAuthenticated Sensitive Information Disclosure in HPE Networking Fabric ComposerEPSS 0.1%CVE-2026-8804MEDIUMCleartext Storage of Sensitive Information for Puppet Resource APIEPSS 0.1%CVE-2023-41096MEDIUMKeys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet devicesEPSS 0.1%CVE-2025-53103MEDIUMJUnit OpenTestReportGeneratingListener can leak Git credentialsEPSS 0.1%CVE-2017-20040MEDIUMSICUNET Access Controller Password Storage cleartext storageEPSS 0.1%CVE-2024-40750MEDIUMLinksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during apEPSS 0.1%CVE-2026-43942MEDIUMelecterm: Full process.env exposed to renderer via window.pre.env in electermEPSS 0.1%CVE-2026-22276MEDIUMDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive InformEPSS 0.1%CVE-2025-3784MEDIUMInformation Disclosure Vulnerability in GX Works2EPSS 0.1%CVE-2025-58401MEDIUMObsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthEPSS 0.1%CVE-2025-14815CRITICALInformation Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64EPSS 0.1%CVE-2025-59105HIGHUnencrypted Flash Storage in dormakaba access managerEPSS 0.1%CVE-2026-93763HIGHSilent plaintext persistence via unresolved callable database name in encryption schema mapEPSS 0.1%