Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2017-3214The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.EPSS 0.6%CVE-2015-8314HIGHThe Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persisEPSS 0.6%CVE-2021-23878HIGHClear text storage of sensitive Information in ENSEPSS 0.6%CVE-2023-24450MEDIUMJenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be EPSS 0.6%CVE-2019-6549An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or SoftwareEPSS 0.6%CVE-2019-18238In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive informatioEPSS 0.6%CVE-2023-4392LOWControl iD Gerencia Web Cookie cleartext storageEPSS 0.6%CVE-2023-27706HIGHBitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other loEPSS 0.6%CVE-2025-34270MEDIUMNagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not ObfuscatedEPSS 0.6%CVE-2020-15085MEDIUMClient caching login operation with plaintext password in Saleor StorefrontEPSS 0.6%CVE-2020-15784A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuEPSS 0.6%CVE-2026-8596HIGHCleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve pathEPSS 0.6%CVE-2024-4235LOWNetgear DG834Gv5 Web Management Interface cleartext storageEPSS 0.6%CVE-2022-43757CRITICALRancher: Exposure of sensitive fieldsEPSS 0.6%CVE-2023-24586LOWCleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authentEPSS 0.5%CVE-2024-4540HIGHKeycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookieEPSS 0.5%CVE-2023-5384HIGHInfinispan: credentials returned from configuration as clear textEPSS 0.5%CVE-2021-20995MEDIUMWAGO: Managed Switches: Storage of user credentials in a cookieEPSS 0.5%CVE-2022-37785HIGHAn issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.EPSS 0.5%CVE-2025-34206CRITICALVasion Print (formerly PrinterLogic) Insecure Shared Storage PermissionsEPSS 0.5%