Falhas do tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2026-86443MEDIUMCleartext Storage of Sensitive Information VulnerabilityEPSS 0.1%CVE-2026-93764HIGHPlaintext storage of encrypted fields via skipped embedded models in encryption schema generationEPSS 0.1%CVE-2025-54855MEDIUMAutomationDirect CLICK PLUS Cleartext Storage of Sensitive InformationEPSS 0.1%CVE-2026-75847MEDIUMSensitive attribute values stored in a non-sensitive public changes map in AshPaperTrailEPSS 0.1%CVE-2024-9432MEDIUMCleartext Storage of Sensitive Information vulnerability has been discovered in OpenText™ Vertica.EPSS 0.1%CVE-2026-77970MEDIUMSensitive fields nested in embedded values are not redacted in AshPaperTrail versionsEPSS 0.1%CVE-2025-7215LOWFNKvision FNK-GU2 wpa_supplicant.conf cleartext storageEPSS 0.1%CVE-2025-48428MEDIUMCleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to thEPSS 0.1%CVE-2025-3395HIGHIncorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.ThEPSS 0.1%CVE-2025-41647MEDIUMLenze: Plaintext Password Disclosure in PLC Designer V4 InterfaceEPSS 0.1%CVE-2026-45362LOWSangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.EPSS 0.1%CVE-2025-40752MEDIUMA vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (EPSS 0.1%CVE-2025-40753MEDIUMA vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (EPSS 0.1%CVE-2025-7397MEDIUMCLI history displays inline passwordsEPSS 0.1%CVE-2025-11009MEDIUMInformation Disclosure Vulnerability in GT Designer3EPSS 0.1%CVE-2024-39674MEDIUMPlaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.1%CVE-2026-36176HIGHGNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows EPSS 0.1%CVE-2025-33081LOWMultiple Vulnerabilities in IBM Concert Software.EPSS 0.1%CVE-2026-76385MEDIUMInformation Disclosure through Action Parameters in Venafi app for Splunk SOAREPSS 0.1%CVE-2025-53755MEDIUMCleartext Storage Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.1%