Falhas do tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2025-53755MEDIUMCleartext Storage Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.1%CVE-2026-66016MEDIUMRendered Artifactory Helm manifests may contain generated TLS private keysEPSS 0.1%CVE-2026-59327MEDIUMCleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch ConfigurationsEPSS 0.1%CVE-2025-54342LOWA vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive IEPSS 0.1%CVE-2026-24311MEDIUMInsecure Storage Protection vulnerability in SAP Customer Checkout 2.0EPSS 0.1%CVE-2025-63729CRITICALAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA CertifEPSS 0.1%CVE-2025-54464HIGHCleartext Storage Vulnerability in ZKTeco WL20EPSS 0.1%CVE-2026-73834MEDIUMMust-gather: must-gather: embedded secret data in acm wrapper crs collected without redactionEPSS 0.1%CVE-2026-28758MEDIUMBIG-IP iControl REST vulnerabilityEPSS 0.1%CVE-2026-42408MEDIUMBIG-IP DNS tmsh vulnerabilityEPSS 0.1%CVE-2025-55717LOWA cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.EPSS 0.1%CVE-2026-18591LOWMeesho Online Shopping App com.meesho.supply cleartext storageEPSS 0.1%CVE-2025-4737MEDIUMInsufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive informatiEPSS 0.1%CVE-2026-55997HIGHLong-lived Rancher registration token exposed in plaintextEPSS 0.1%CVE-2026-34490MEDIUMXAAP Android Data Stored in Unencrypted DatabaseEPSS 0.1%CVE-2026-41520HIGHCillium exposes sensitive information included in the cilium-bugtool debug archiveEPSS 0.1%CVE-2026-16802MEDIUMCleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local EPSS 0.1%CVE-2025-2909MEDIUMLack of encryption vulnerability in DuoxMeEPSS 0.1%CVE-2026-4130HIGHStorage of Sensitive Information in Cleartext in NI SystemLinkEPSS 0.1%CVE-2026-80058MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage EPSS 0.1%